Skip to content

fix(security): remediate highest-risk Sonar findings - #18

Merged
aksOps merged 2 commits into
mainfrom
fix/sonar-security-batch-1
Aug 1, 2026
Merged

fix(security): remediate highest-risk Sonar findings#18
aksOps merged 2 commits into
mainfrom
fix/sonar-security-batch-1

Conversation

@aksOps

@aksOps aksOps commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Summary\n\n- fix three critical deterministic set-ordering bugs\n- harden outbox persistence and legacy migration against schema-tainted payloads\n- validate GitHub API path segments before request construction\n- add explicit Git option boundaries for validated revision operands\n\n## Verification\n\n- 902 frontend tests passed\n- frontend coverage: 98.23% statements, 95.21% branches, 98.72% functions, 99.43% lines\n- every Go package >=95%; aggregate 96.4%\n- Go race, vet, formatting, frontend build, Actionlint, ShellCheck, action-pin checks, CI hostile fixtures, npm audit all passed\n- independent code review: APPROVE\n\n## Sonar reconciliation\n\nTen separately reviewed SQL/confetti false positives are already resolved. This PR should close three bugs and five vulnerabilities on the exact candidate revision.

Comment thread scripts/ci/validate-workflow-run.cjs Fixed
@sonarqubecloud

sonarqubecloud Bot commented Aug 1, 2026

Copy link
Copy Markdown

@aksOps
aksOps merged commit 13ef94c into main Aug 1, 2026
13 checks passed
@aksOps
aksOps deleted the fix/sonar-security-batch-1 branch August 1, 2026 15:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants