Skip to content

fix(smus): dispose authprovider and then dz clients when signing out …

9083350
Select commit
Loading
Failed to load commit list.
Open

Merge master into feature/ui-e2e-tests #8426

fix(smus): dispose authprovider and then dz clients when signing out …
9083350
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL failed Dec 23, 2025 in 11s

10 new alerts including 10 high severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 10 high

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 245 in .github/workflows/node.js.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{contents: read}}

Check failure on line 170 in packages/core/src/auth/auth.ts

See this annotation in the file changed.

Code scanning / CodeQL

Polynomial regular expression used on uncontrolled data High

This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '#'.

Check failure on line 52 in packages/core/src/awsService/sagemaker/detached-server/routes/getSession.ts

See this annotation in the file changed.

Code scanning / CodeQL

Use of externally-controlled format string High

Format string depends on a
user-provided value
.

Check failure on line 31 in packages/core/src/codewhisperer/util/importAdderUtil.ts

See this annotation in the file changed.

Code scanning / CodeQL

Polynomial regular expression used on uncontrolled data High

This
regular expression
that depends on
library input
may run slow on strings with many repetitions of ' '.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of ' '.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of ' '.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of ' '.

Check failure on line 65 in packages/core/src/codewhisperer/util/importAdderUtil.ts

See this annotation in the file changed.

Code scanning / CodeQL

Polynomial regular expression used on uncontrolled data High

This
regular expression
that depends on
library input
may run slow on strings starting with '=require(' and with many repetitions of '=require(!'.
This
regular expression
that depends on
library input
may run slow on strings starting with '=require(' and with many repetitions of '=require(!'.
This
regular expression
that depends on
library input
may run slow on strings starting with '=require(' and with many repetitions of '=require(!'.
This
regular expression
that depends on
library input
may run slow on strings starting with '=require(' and with many repetitions of '=require(!'.

Check failure on line 559 in packages/core/src/sagemakerunifiedstudio/explorer/nodes/s3Strategy.ts

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High

This replaces only the first occurrence of '*'.

Check failure on line 94 in packages/core/src/shared/utilities/proxyUtil.ts

See this annotation in the file changed.

Code scanning / CodeQL

Disabling certificate validation High

Disabling certificate validation is strongly discouraged.

Check failure on line 56 in packages/core/src/shared/utilities/textUtilities.ts

See this annotation in the file changed.

Code scanning / CodeQL

Polynomial regular expression used on uncontrolled data High

This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.

Check failure on line 58 in packages/core/src/shared/utilities/textUtilities.ts

See this annotation in the file changed.

Code scanning / CodeQL

Polynomial regular expression used on uncontrolled data High

This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.

Check failure on line 66 in packages/core/src/test/awsService/cloudformation/consoleLinksUtils.test.ts

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete URL substring sanitization High test

'
eu-west-1.console.aws.amazon.com
' can be anywhere in the URL, and arbitrary hosts may come before or after it.

Check failure on line 52 in packages/core/src/test/shared/extensions/ssh.test.ts

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High test

This replaces only the first occurrence of '"'.