Skip to content

fix(security): resolve remaining 109 CodeQL empty-except and chmod permission alerts - #4

Merged
dalroot merged 1 commit into
masterfrom
fix/codeql-final-remediation
Oct 4, 2026
Merged

dalroot merged 1 commit into
masterfrom
fix/codeql-final-remediation

Conversation

@dalroot

@dalroot dalroot commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Final CodeQL Remediation

This PR resolves the remaining 109 CodeQL alerts:

  • py/empty-except (94 alerts): Added explanatory comments in except handlers across app/server.py, agent/agent.py, app/static/js/agent.py, app/db.py, app/auth.py, app/geoip.py, and bin/hawal.
  • py/overly-permissive-file (13 alerts): Tightened file permissions from 0o750 to secure user-only execution mode 0o700.
  • py/catch-base-exception (2 alerts): Replaced inline except: pass with specific except (ProcessLookupError, OSError):.

All tests pass cleanly.

@dalroot
dalroot merged commit cbfe234 into master Oct 4, 2026
6 checks passed
@dalroot
dalroot deleted the fix/codeql-final-remediation branch October 4, 2026 22:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant