Skip to content

chore: replace main's tree with v2 - #1830

Merged
cliffhall merged 521 commits into
mainfrom
chore/v2-golive
Jul 28, 2026
Merged

cliffhall merged 521 commits into
mainfrom
chore/v2-golive

chore: replace main's tree with v2

ec5d8e1
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL failed Jul 28, 2026 in 3s

10 new alerts including 1 critical severity security vulnerability

New alerts in code changed by this pull request

Security Alerts:

  • 1 critical
  • 9 high

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 121 in clients/web/src/test/core/auth/ema/emaFlow.test.ts

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete URL substring sanitization High test

'
https://idp.ema.test
' may be followed by an arbitrary host name.

Check failure on line 154 in clients/web/src/test/core/auth/ema/emaFlow.test.ts

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete URL substring sanitization High test

'
https://as.ema.test
' may be followed by an arbitrary host name.

Check failure on line 279 in clients/web/src/test/core/auth/ema/emaFlow.test.ts

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete URL substring sanitization High test

'
https://idp.ema.test
' may be followed by an arbitrary host name.

Check failure on line 303 in clients/web/src/test/core/auth/ema/emaFlow.test.ts

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete URL substring sanitization High test

'
https://as.ema.test
' may be followed by an arbitrary host name.

Check failure on line 49 in clients/web/src/test/integration/server/inject-auth-token.test.ts

See this annotation in the file changed.

Code scanning / CodeQL

Bad HTML filtering regexp High test

This regular expression does not match upper case <SCRIPT> tags.

Check failure on line 1084 in test-servers/src/composable-test-server.ts

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High test

This does not escape backslash characters in the input.

Check failure on line 229 in test-servers/src/test-server-oauth.ts

See this annotation in the file changed.

Code scanning / CodeQL

Missing rate limiting High test

This route handler performs
authorization
, but is not rate-limited.
This route handler performs
authorization
, but is not rate-limited.

Check failure on line 247 in test-servers/src/test-server-oauth.ts

See this annotation in the file changed.

Code scanning / CodeQL

Missing rate limiting High test

This route handler performs
authorization
, but is not rate-limited.
This route handler performs
authorization
, but is not rate-limited.

Check failure on line 627 in test-servers/src/test-server-oauth.ts

See this annotation in the file changed.

Code scanning / CodeQL

Insecure randomness High test

This uses a cryptographically insecure random number generated at
Math.random()
in a security context.

Check failure on line 703 in test-servers/src/test-server-oauth.ts

See this annotation in the file changed.

Code scanning / CodeQL

Server-side request forgery Critical test

The
URL
of this request depends on a
user-provided value
.
The
URL
of this request depends on a
user-provided value
.
The
URL
of this request depends on a
user-provided value
.
The
URL
of this request depends on a
user-provided value
.
The
URL
of this request depends on a user-provided value.
The
URL
of this request depends on a user-provided value.