Skip to content

fix: resolve the three high code-scanning alerts in the helper scripts - #193

Merged
catinspace-au merged 1 commit into
mainfrom
fix/codeql-high-alerts
Sep 30, 2026
Merged

catinspace-au merged 1 commit into
mainfrom
fix/codeql-high-alerts

Conversation

@catinspace-au

@catinspace-au catinspace-au commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Clears alert #3 and records why #1 and #2 are not leaks. No behaviour change.

The ancestor-override test now asserts the whole list, so the external origin's absence and the override's position are both checked and there is no URL membership test left to misread as a substring check. The two clear-text logging sinks carry a codeql marker with the reason: creds.py prints the admin login on a terminal because that is what make creds is for, and every flow traced into _print carries a key name, a committed default or an already-redacted fault.
@catinspace-au
catinspace-au merged commit cab0827 into main Sep 30, 2026
7 checks passed
@catinspace-au
catinspace-au deleted the fix/codeql-high-alerts branch September 30, 2026 14:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Investigate: Make vs hyperi-ci for stack lifecycle in dfe-docker

1 participant