Skip to content

fix(security): check a Stream Deck route is a function before calling it - #62

Merged
DarrellVS merged 1 commit into
devfrom
codeql-17-typeof
Sep 23, 2026
Merged

DarrellVS merged 1 commit into
devfrom
codeql-17-typeof

Conversation

@DarrellVS

Copy link
Copy Markdown
Owner

Alert 17 stayed open on 3.5.1: code scanning wants the value checked as callable before a request-chosen route is called. Adds the typeof guard. Verified: CodeQL on probe PR #61 into main passes with no open alerts.

🤖 Generated with Claude Code

Code scanning still reported alert 17 on 3.5.1, at the call rather than the
lookup: with a key chosen by the request, it wants the value checked as
callable first. The Map from 3.5.1 already limits it to the listed routes;
this adds the typeof guard the rule recognises.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@DarrellVS DarrellVS added the security Code scanning and hardening label Sep 23, 2026
@DarrellVS DarrellVS self-assigned this Sep 23, 2026
@DarrellVS
DarrellVS merged commit 9a084d6 into dev Sep 23, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Code scanning and hardening

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant