Skip to content

fix(security): the three code scanning alerts 3.5.0 raised - #60

Merged
DarrellVS merged 1 commit into
devfrom
codeql-3.5.0-followups
Sep 23, 2026
Merged

DarrellVS merged 1 commit into
devfrom
codeql-3.5.0-followups

Conversation

@DarrellVS

Copy link
Copy Markdown
Owner

Follow-ups for the three CodeQL alerts raised on main after 3.5.0.

npm run check 866; streamdeck-check.mjs passes.

🤖 Generated with Claude Code

- **Stream Deck routes are looked up as own properties** (alert 17). The
  key is built from the request, and a bare `ROUTES[key]` also finds what
  every object inherits. `Object.hasOwn` first.
- **A batch log line keeps the clip id out of its format string**
  (alert 18), where a `%s` would be read as a directive.
- Alert 19 is `tagPatternRules.ts` compiling a tag rule the user wrote,
  which is the feature, and is dismissed as won't fix the same way alert
  15 was; that file is the mitigation.

`npm run check` 866; `streamdeck-check.mjs` exit 0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@DarrellVS DarrellVS added bug Something isn't working security Code scanning and hardening labels Sep 23, 2026
@DarrellVS DarrellVS self-assigned this Sep 23, 2026
@DarrellVS
DarrellVS merged commit f25a3d4 into dev Sep 23, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working security Code scanning and hardening

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant