Skip to content

Alert autofix 821.23 - #22800

Closed
krishnprakash wants to merge 28 commits into
github:mainfrom
krishnprakash:alert-autofix-821.23
Closed

krishnprakash wants to merge 28 commits into
github:mainfrom
krishnprakash:alert-autofix-821.23

Conversation

@krishnprakash

Copy link
Copy Markdown

No description provided.

dependabot Bot and others added 28 commits October 8, 2026 09:17
Bumps the npm_and_yarn group with 2 updates in the /javascript/ql/test/library-tests/HtmlSanitizers directory: [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) and [validator](https://github.com/validatorjs/validator.js).
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/library-tests/frameworks/Next directory: [next](https://github.com/vercel/next.js).
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss directory: [next](https://github.com/vercel/next.js).
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-079/ReflectedXss directory: [next](https://github.com/vercel/next.js).
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-200/lib directory: [async](https://github.com/caolan/async).
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-915/PrototypePollutingMergeCall/src-non-vulnerable-lodash directory: [lodash](https://github.com/lodash/lodash).
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-915/PrototypePollutingMergeCall/src-vulnerable-lodash directory: [lodash](https://github.com/lodash/lodash).
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-918/Request directory: [next](https://github.com/vercel/next.js).


Updates `sanitize-html` from 1.27.5 to 2.18.0
- [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md)
- [Commits](https://github.com/apostrophecms/apostrophe/commits/sanitize-html@2.18.0/packages/sanitize-html)

Updates `validator` from 10.11.0 to 13.15.35
- [Release notes](https://github.com/validatorjs/validator.js/releases)
- [Changelog](https://github.com/validatorjs/validator.js/blob/master/CHANGELOG.md)
- [Commits](validatorjs/validator.js@10.11.0...13.15.35)

Updates `next` from 10.2.3 to 16.4.0
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v10.2.3...v16.4.0)

Updates `next` from 10.2.3 to 16.4.0
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v10.2.3...v16.4.0)

Updates `next` from 10.2.3 to 16.4.0
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v10.2.3...v16.4.0)

Updates `async` from 3.2.0 to 3.2.2
- [Release notes](https://github.com/caolan/async/releases)
- [Changelog](https://github.com/caolan/async/blob/master/CHANGELOG.md)
- [Commits](caolan/async@v3.2.0...v3.2.2)

Updates `lodash` from 4.17.12 to 4.18.1
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.12...4.18.1)

Updates `lodash` from 4.17.4 to 4.18.1
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.12...4.18.1)

Updates `next` from 15.1.7 to 15.5.27
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v10.2.3...v16.4.0)

---
updated-dependencies:
- dependency-name: sanitize-html
  dependency-version: 2.18.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: validator
  dependency-version: 13.15.35
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: next
  dependency-version: 16.4.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: next
  dependency-version: 16.4.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: next
  dependency-version: 16.4.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: async
  dependency-version: 3.2.2
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: lodash
  dependency-version: 4.18.1
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: lodash
  dependency-version: 4.18.1
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: next
  dependency-version: 15.5.27
  dependency-type: direct:production
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [lazy_static](https://github.com/rust-lang-nursery/lazy-static.rs) from 1.5.0 to 1.5.1.
- [Release notes](https://github.com/rust-lang-nursery/lazy-static.rs/releases)
- [Commits](https://github.com/rust-lang-nursery/lazy-static.rs/commits)

---
updated-dependencies:
- dependency-name: lazy_static
  dependency-version: 1.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](actions/checkout@v5...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tree-sitter](https://github.com/tree-sitter/tree-sitter) from 0.26.13 to 0.27.0.
- [Release notes](https://github.com/tree-sitter/tree-sitter/releases)
- [Commits](tree-sitter/tree-sitter@v0.26.13...v0.27.0)

---
updated-dependencies:
- dependency-name: tree-sitter
  dependency-version: 0.27.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 6.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4...v6)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…ibrary-tests/HtmlSanitizers/npm_and_yarn-2bfa92aa80
…vascript/ql/test/library-tests/HtmlSanitizers/npm_and_yarn-2bfa92aa80

Bump the npm_and_yarn group across 8 directories with 5 updates
Bumps [golang.org/x/text](https://github.com/golang/text) from 0.8.0 to 0.42.0.
- [Release notes](https://github.com/golang/text/releases)
- [Commits](golang/text@v0.8.0...v0.42.0)

---
updated-dependencies:
- dependency-name: golang.org/x/text
  dependency-version: 0.42.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [golang.org/x/sys](https://github.com/golang/sys) from 0.6.0 to 0.49.0.
- [Commits](golang/sys@v0.6.0...v0.49.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sys
  dependency-version: 0.49.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…actions/checkout-7

Bump actions/checkout from 5 to 7
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 7.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v4...v7)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…tatic-1.5.1

Bump lazy_static from 1.5.0 to 1.5.1 in /ql
…actions/upload-artifact-6

Bump actions/upload-artifact from 4 to 6
…itter-0.27.0

Bump tree-sitter from 0.26.13 to 0.27.0 in /ql
…ts/semmle/go/frameworks/Fasthttp/golang.org/x/text-0.42.0
…l/test/library-tests/semmle/go/frameworks/Fasthttp/golang.org/x/text-0.42.0

Bump golang.org/x/text from 0.8.0 to 0.42.0 in /go/ql/test/library-tests/semmle/go/frameworks/Fasthttp
…ts/semmle/go/frameworks/Fasthttp/golang.org/x/sys-0.49.0
…l/test/library-tests/semmle/go/frameworks/Fasthttp/golang.org/x/sys-0.49.0

Bump golang.org/x/sys from 0.6.0 to 0.49.0 in /go/ql/test/library-tests/semmle/go/frameworks/Fasthttp
…actions/download-artifact-7

Bump actions/download-artifact from 4 to 7
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Phileco <132178579+krishnprakash@users.noreply.github.com>
Potential fix for code scanning alert no. 820: Generic catch clause
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Phileco <132178579+krishnprakash@users.noreply.github.com>
Potential fix for code scanning alert no. 821: Generic catch clause
@krishnprakash
krishnprakash requested review from a team as code owners October 9, 2026 17:16
@jketema

jketema commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Tests should not be changed.

@jketema jketema closed this Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants