Skip to content

Conversation

@vlussenburg
Copy link
Contributor

@vlussenburg vlussenburg commented Dec 3, 2025

@vim-zz Note: maybe the path traversal stuff is already covered in readFile() . I am just not sure I can include that here.

Copy link

@orca-security-us orca-security-us bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Orca Security Scan Summary

Status Check Issues by priority
Passed Passed Infrastructure as Code high 0   medium 0   low 0   info 0 View in Orca
Passed Passed SAST high 0   medium 3   low 0   info 0 View in Orca
Passed Passed Secrets high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Vulnerabilities high 0   medium 0   low 0   info 0 View in Orca
🛡️ The following SAST misconfigurations have been detected
NAME FILE
medium Dynamic File Path Construction from User Input Can Lead to Path Traversal Attacks ...wnWithLinks/index.js View in code
medium Prevent Regular Expression Denial of Service in User Input Validation ...wnWithLinks/index.js View in code
medium Prevent Regular Expression Denial of Service in User Input Validation ...ownWithLinks/test.js View in code

@vlussenburg vlussenburg marked this pull request as ready for review December 3, 2025 16:19
@vlussenburg
Copy link
Contributor Author

/gs review

@vlussenburg vlussenburg marked this pull request as draft December 3, 2025 16:35
Copy link

@orca-security-us orca-security-us bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Orca Security Scan Summary

Status Check Issues by priority
Passed Passed Infrastructure as Code high 0   medium 0   low 0   info 0 View in Orca
Passed Passed SAST high 0   medium 2   low 0   info 0 View in Orca
Passed Passed Secrets high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Vulnerabilities high 0   medium 0   low 0   info 0 View in Orca
🛡️ The following SAST misconfigurations have been detected
NAME FILE
medium Dynamic File Path Construction from User Input Can Lead to Path Traversal Attacks ...wnWithLinks/index.js View in code
medium Prevent Regular Expression Denial of Service in User Input Validation ...wnWithLinks/index.js View in code

@vlussenburg vlussenburg marked this pull request as ready for review December 3, 2025 17:20
@vim-zz vim-zz enabled auto-merge (squash) December 4, 2025 09:57
@vim-zz vim-zz disabled auto-merge December 7, 2025 11:21
@vim-zz vim-zz merged commit c65081b into linear-b:main Dec 7, 2025
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants