Skip to content

Resolve existing CodeQL alerts #26

@cbusillo

Description

@cbusillo

Problem

During the workflow metadata rollout, GitHub code scanning showed 3 existing open alerts:

These appear to be pre-existing findings and are not introduced by the workflow metadata PR.

Direction

Resolve or explicitly triage the CodeQL alerts in a focused security/quality cleanup pass.

Acceptance Criteria

  • Each open CodeQL alert is either fixed or documented as a justified false positive/suppression.
  • CI and repo quality gates pass after the changes.
  • GitHub code scanning is rechecked and the alert count is reduced or the remaining state is explicitly explained.

Migrated from bot-authored issue #20 because shiny-code-bot is awaiting spam appeal. Original created: 2026-04-29T19:48:00Z.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions