fix: address all 18 code scanning security vulnerabilities#83
Merged
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
e0e1bf1 to
d4209dd
Compare
Owner
Author
|
I don't know why Mistral decided to close the PR... |
- Added Subresource Integrity to CDN scripts (Alert 18) - Fixed URL validation to use proper parsing (Alerts 17-16) - Added security warnings for MD5 usage (Alerts 10-7, 6-5-4) - Limited test socket binding to localhost (Alert 15) - Redacted API keys in logging (Alerts 12-11) - Added GitHub Actions permissions (Alerts 3-2-1) - Fixed test assertions to use hostname instead of netloc All security vulnerabilities have been addressed while maintaining full compatibility with the Supernote Private Cloud protocol.
27eb1c7 to
5087f53
Compare
5087f53 to
5de7a90
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
All security vulnerabilities have been addressed while maintaining full compatibility with the Supernote Private Cloud protocol.