Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[pull] main from microsoft:main #31

Open
wants to merge 3,470 commits into
base: main
Choose a base branch
from

fix: avoid race condition crash in `[RCTDataRequestHandler invalidate…

c541c8c
Select commit
Loading
Failed to load commit list.
Open

[pull] main from microsoft:main #31

fix: avoid race condition crash in `[RCTDataRequestHandler invalidate…
c541c8c
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL failed Feb 27, 2025 in 4s

44 new alerts including 38 high severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 38 high
  • 6 medium

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 1 in packages/debugger-frontend/dist/third-party/front_end/core/common/common.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete URL scheme check High library

This check does not consider vbscript:.

Check failure on line 1 in packages/debugger-frontend/dist/third-party/front_end/core/platform/platform.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete multi-character sanitization High library

This string may still contain
<!--
, which may cause an HTML element injection vulnerability.

Check failure on line 1 in packages/debugger-frontend/dist/third-party/front_end/core/platform/platform.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete multi-character sanitization High library

This string may still contain
<!--
, which may cause an HTML element injection vulnerability.

Check failure on line 1 in packages/debugger-frontend/dist/third-party/front_end/core/platform/platform.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete multi-character sanitization High library

This string may still contain
<!--
, which may cause an HTML element injection vulnerability.

Check failure on line 1 in packages/debugger-frontend/dist/third-party/front_end/core/platform/platform.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete multi-character sanitization High library

This string may still contain
<!--
, which may cause an HTML element injection vulnerability.

Check warning on line 1 in packages/debugger-frontend/dist/third-party/front_end/entrypoints/formatter_worker/formatter_worker.js

See this annotation in the file changed.

Code scanning / CodeQL

Overly permissive regular expression range Medium library

Suspicious character range that overlaps with a-f in the same character class, and is equivalent to [A-Z[]^_`a-f].

Check warning on line 1 in packages/debugger-frontend/dist/third-party/front_end/entrypoints/formatter_worker/formatter_worker.js

See this annotation in the file changed.

Code scanning / CodeQL

Overly permissive regular expression range Medium library

Suspicious character range that overlaps with a-f in the same character class, and is equivalent to [A-Z[]^_`a-f].

Check warning on line 1 in packages/debugger-frontend/dist/third-party/front_end/entrypoints/formatter_worker/formatter_worker.js

See this annotation in the file changed.

Code scanning / CodeQL

Overly permissive regular expression range Medium library

Suspicious character range that overlaps with a-f in the same character class, and is equivalent to [A-Z[]^_`a-f].

Check failure on line 1 in packages/debugger-frontend/dist/third-party/front_end/legacy_test_runner/test_runner/test_runner.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High library test

This does not escape backslash characters in the input.

Check failure on line 41 in packages/debugger-frontend/dist/third-party/front_end/panels/application/application.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete URL scheme check High library

This check does not consider vbscript:.

Check failure on line 1 in packages/debugger-frontend/dist/third-party/front_end/panels/network/network.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High library

This does not escape backslash characters in the input.

Check failure on line 1 in packages/debugger-frontend/dist/third-party/front_end/third_party/codemirror.next/chunk/codemirror.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High library

This replaces only the first occurrence of /&/.

Check failure on line 1 in packages/debugger-frontend/dist/third-party/front_end/third_party/codemirror.next/chunk/codemirror.js

See this annotation in the file changed.

Code scanning / CodeQL

Useless regular-expression character escape High library

The escape sequence '\b' is a backspace, and not a word-boundary assertion when it is used in a
regular expression
.

Check failure on line 114 in packages/debugger-frontend/dist/third-party/front_end/third_party/csp_evaluator/csp_evaluator.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High library

This replaces only the first occurrence of "*".

Check failure on line 114 in packages/debugger-frontend/dist/third-party/front_end/third_party/csp_evaluator/csp_evaluator.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High library

This replaces only the first occurrence of "*".

Check failure on line 1281 in packages/debugger-frontend/dist/third-party/front_end/third_party/lighthouse/lighthouse-dt-bundle.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High library

This does not escape backslash characters in the input.

Check failure on line 1793 in packages/debugger-frontend/dist/third-party/front_end/third_party/lighthouse/lighthouse-dt-bundle.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High library

This replaces only the first occurrence of "*".

Check failure on line 1793 in packages/debugger-frontend/dist/third-party/front_end/third_party/lighthouse/lighthouse-dt-bundle.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High library

This replaces only the first occurrence of "*".

Check failure on line 2005 in packages/debugger-frontend/dist/third-party/front_end/third_party/lighthouse/lighthouse-dt-bundle.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete URL scheme check High library

This check does not consider data: and vbscript:.

Check failure on line 2056 in packages/debugger-frontend/dist/third-party/front_end/third_party/lighthouse/lighthouse-dt-bundle.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete regular expression for hostnames High library

This string, which is used as a regular expression
here
, has an unescaped '.' before 'prebid[.]org/', so it might match more hosts than expected.

Check failure on line 2056 in packages/debugger-frontend/dist/third-party/front_end/third_party/lighthouse/lighthouse-dt-bundle.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete regular expression for hostnames High library

This string, which is used as a regular expression
here
, has an unescaped '.' before 'adtechus[.]com/', so it might match more hosts than expected.

Check failure on line 2058 in packages/debugger-frontend/dist/third-party/front_end/third_party/lighthouse/lighthouse-dt-bundle.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete regular expression for hostnames High library

This string, which is used as a regular expression
here
, has an unescaped '.' before 'criteo[.]com/cdb', so it might match more hosts than expected.

Check failure on line 2058 in packages/debugger-frontend/dist/third-party/front_end/third_party/lighthouse/lighthouse-dt-bundle.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete regular expression for hostnames High library

This string, which is used as a regular expression
here
, has an unescaped '.' before 'criteo[.]com/delivery/rta', so it might match more hosts than expected.

Check failure on line 2058 in packages/debugger-frontend/dist/third-party/front_end/third_party/lighthouse/lighthouse-dt-bundle.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete regular expression for hostnames High library

This string, which is used as a regular expression
here
, has an unescaped '.' before 'criteo[.]com/delivery/rta', so it might match more hosts than expected.

Check failure on line 2060 in packages/debugger-frontend/dist/third-party/front_end/third_party/lighthouse/lighthouse-dt-bundle.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete regular expression for hostnames High library

This string, which is used as a regular expression
here
, has an unescaped '.' before 'openx[.]net/w/1', so it might match more hosts than expected.