Skip to content

fix(security): resolve CodeQL alerts 129-135 - #216

Merged
kevintseng merged 1 commit into
mainfrom
fix/codeql-alerts-129-135
Aug 28, 2026
Merged

fix(security): resolve CodeQL alerts 129-135#216
kevintseng merged 1 commit into
mainfrom
fix/codeql-alerts-129-135

Conversation

@kevintseng

Copy link
Copy Markdown
Contributor

Closes the seven open CodeQL findings without dismissing alerts or removing supported functionality.\n\n- replace check-then-open/read patterns with atomic creation or same-descriptor validation\n- preserve ACP post-open inode identity defense\n- open Windows feedback URLs through direct explorer.exe argv instead of cmd.exe parsing\n- await the existing in-flight router promise\n- regenerate committed dist artifacts\n\nVerification: npm run verify:release; focused security regression suites (37 passed, 3 platform-skipped).

@kevintseng
kevintseng merged commit bad8eaa into main Aug 28, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant