Skip to content

fix(*): address security findings on next - #19

Merged
omermorad merged 1 commit into
nextfrom
fix/advanced-security-findings
Sep 29, 2026
Merged

omermorad merged 1 commit into
nextfrom
fix/advanced-security-findings

Conversation

@omermorad

@omermorad omermorad commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fresh branch from origin/next (53d3a39), containing only the fixes for the three github-advanced-security comments on #15 and their regression tests.

  • Findings fix: build step should not contain watch #1 and move to pnpm #2: remove caller-selected checkout from Release Preview; only run from next, check out next explicitly, and do not persist Git credentials. The workflow remains read-only and does not use caches.
  • Finding Temp/temp #3: parse schema URLs and require the official hostname, HTTP(S), and a supported draft path instead of accepting substring matches.
  • Add 16 regression cases for legitimate schema URLs, spoofed hosts/paths/query strings, malformed identifiers, and workflow trust boundaries.

Original comments

Validation

  • pnpm build: passed
  • pnpm lint: passed
  • Targeted security regression tests: 16 passed
  • pnpm test:e2e: 337 passed, 1 skipped.

This is not stacked on #17 or #18. The broader dependency remediation remains in #18; its overlapping CodeQL fixes should be reconciled after this focused PR merges. Existing next CI and package metadata are otherwise unchanged.

No alerts were dismissed. No tags, releases, or package publications were created.

@omermorad omermorad changed the title fix(*): address Advanced Security findings on next fix(*): address security findings on next Sep 29, 2026
@omermorad omermorad self-assigned this Sep 29, 2026
@omermorad
omermorad merged commit 2466cd3 into next Sep 29, 2026
13 checks passed
@omermorad
omermorad deleted the fix/advanced-security-findings branch September 29, 2026 06:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant