Repository navigation
Alert autofix 821.23 - #22800
Closed
krishnprakash wants to merge 28 commits into
Closed
Alert autofix 821.23#22800krishnprakash wants to merge 28 commits into
krishnprakash wants to merge 28 commits into
Conversation
Bumps the npm_and_yarn group with 2 updates in the /javascript/ql/test/library-tests/HtmlSanitizers directory: [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) and [validator](https://github.com/validatorjs/validator.js). Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/library-tests/frameworks/Next directory: [next](https://github.com/vercel/next.js). Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss directory: [next](https://github.com/vercel/next.js). Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-079/ReflectedXss directory: [next](https://github.com/vercel/next.js). Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-200/lib directory: [async](https://github.com/caolan/async). Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-915/PrototypePollutingMergeCall/src-non-vulnerable-lodash directory: [lodash](https://github.com/lodash/lodash). Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-915/PrototypePollutingMergeCall/src-vulnerable-lodash directory: [lodash](https://github.com/lodash/lodash). Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-918/Request directory: [next](https://github.com/vercel/next.js). Updates `sanitize-html` from 1.27.5 to 2.18.0 - [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md) - [Commits](https://github.com/apostrophecms/apostrophe/commits/sanitize-html@2.18.0/packages/sanitize-html) Updates `validator` from 10.11.0 to 13.15.35 - [Release notes](https://github.com/validatorjs/validator.js/releases) - [Changelog](https://github.com/validatorjs/validator.js/blob/master/CHANGELOG.md) - [Commits](validatorjs/validator.js@10.11.0...13.15.35) Updates `next` from 10.2.3 to 16.4.0 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v10.2.3...v16.4.0) Updates `next` from 10.2.3 to 16.4.0 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v10.2.3...v16.4.0) Updates `next` from 10.2.3 to 16.4.0 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v10.2.3...v16.4.0) Updates `async` from 3.2.0 to 3.2.2 - [Release notes](https://github.com/caolan/async/releases) - [Changelog](https://github.com/caolan/async/blob/master/CHANGELOG.md) - [Commits](caolan/async@v3.2.0...v3.2.2) Updates `lodash` from 4.17.12 to 4.18.1 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.12...4.18.1) Updates `lodash` from 4.17.4 to 4.18.1 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.12...4.18.1) Updates `next` from 15.1.7 to 15.5.27 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v10.2.3...v16.4.0) --- updated-dependencies: - dependency-name: sanitize-html dependency-version: 2.18.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: validator dependency-version: 13.15.35 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: next dependency-version: 16.4.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: next dependency-version: 16.4.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: next dependency-version: 16.4.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: async dependency-version: 3.2.2 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: lodash dependency-version: 4.18.1 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: lodash dependency-version: 4.18.1 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: next dependency-version: 15.5.27 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [lazy_static](https://github.com/rust-lang-nursery/lazy-static.rs) from 1.5.0 to 1.5.1. - [Release notes](https://github.com/rust-lang-nursery/lazy-static.rs/releases) - [Commits](https://github.com/rust-lang-nursery/lazy-static.rs/commits) --- updated-dependencies: - dependency-name: lazy_static dependency-version: 1.5.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Commits](actions/checkout@v5...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tree-sitter](https://github.com/tree-sitter/tree-sitter) from 0.26.13 to 0.27.0. - [Release notes](https://github.com/tree-sitter/tree-sitter/releases) - [Commits](tree-sitter/tree-sitter@v0.26.13...v0.27.0) --- updated-dependencies: - dependency-name: tree-sitter dependency-version: 0.27.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 6. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v6) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…ibrary-tests/HtmlSanitizers/npm_and_yarn-2bfa92aa80
…vascript/ql/test/library-tests/HtmlSanitizers/npm_and_yarn-2bfa92aa80 Bump the npm_and_yarn group across 8 directories with 5 updates
Bumps [golang.org/x/text](https://github.com/golang/text) from 0.8.0 to 0.42.0. - [Release notes](https://github.com/golang/text/releases) - [Commits](golang/text@v0.8.0...v0.42.0) --- updated-dependencies: - dependency-name: golang.org/x/text dependency-version: 0.42.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [golang.org/x/sys](https://github.com/golang/sys) from 0.6.0 to 0.49.0. - [Commits](golang/sys@v0.6.0...v0.49.0) --- updated-dependencies: - dependency-name: golang.org/x/sys dependency-version: 0.49.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
…actions/checkout-7 Bump actions/checkout from 5 to 7
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 7. - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v4...v7) --- updated-dependencies: - dependency-name: actions/download-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…tatic-1.5.1 Bump lazy_static from 1.5.0 to 1.5.1 in /ql
…actions/upload-artifact-6 Bump actions/upload-artifact from 4 to 6
…itter-0.27.0 Bump tree-sitter from 0.26.13 to 0.27.0 in /ql
…ts/semmle/go/frameworks/Fasthttp/golang.org/x/text-0.42.0
…l/test/library-tests/semmle/go/frameworks/Fasthttp/golang.org/x/text-0.42.0 Bump golang.org/x/text from 0.8.0 to 0.42.0 in /go/ql/test/library-tests/semmle/go/frameworks/Fasthttp
…ts/semmle/go/frameworks/Fasthttp/golang.org/x/sys-0.49.0
…l/test/library-tests/semmle/go/frameworks/Fasthttp/golang.org/x/sys-0.49.0 Bump golang.org/x/sys from 0.6.0 to 0.49.0 in /go/ql/test/library-tests/semmle/go/frameworks/Fasthttp
…actions/download-artifact-7 Bump actions/download-artifact from 4 to 7
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> Signed-off-by: Phileco <132178579+krishnprakash@users.noreply.github.com>
Potential fix for code scanning alert no. 820: Generic catch clause
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> Signed-off-by: Phileco <132178579+krishnprakash@users.noreply.github.com>
Potential fix for code scanning alert no. 821: Generic catch clause
Contributor
|
Tests should not be changed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.