Skip to content

Dev to main - #3

Merged
chendelin1982 merged 78 commits into
mainfrom
dev
Jul 20, 2026
Merged

Dev to main#3
chendelin1982 merged 78 commits into
mainfrom
dev

fix ci gate

82b0be5
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL failed Jul 20, 2026 in 8s

46 new alerts including 6 critical severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 6 critical
  • 33 high
  • 7 medium

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 151 in .github/workflows/_quality-gate.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 18 in .github/workflows/post-merge.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {}

Check warning on line 16 in .github/workflows/pr-gate.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {}

Check warning on line 38 in .github/workflows/remote-playwright.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 15 in .github/workflows/staging-gate.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {}

Check failure on line 107 in web/src/routes/_app/_auth/_superuser/logs.tsx

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High

This does not escape backslash characters in the input.

Check failure on line 270 in web/src/routes/_app/_auth/feeds.tsx

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete URL scheme check High

This check does not consider data: and vbscript:.

Check failure on line 273 in backend/domain/terminal/ssh_exec.go

See this annotation in the file changed.

Code scanning / CodeQL

Command built from user-controlled sources Critical

This command depends on a
user-provided value
.

Check failure on line 115 in backend/infra/docker/ssh.go

See this annotation in the file changed.

Code scanning / CodeQL

Command built from user-controlled sources Critical

This command depends on a
user-provided value
.
This command depends on a
user-provided value
.
This command depends on a
user-provided value
.
This command depends on a
user-provided value
.
This command depends on a
user-provided value
.

Check failure on line 211 in backend/infra/docker/ssh.go

See this annotation in the file changed.

Code scanning / CodeQL

Size computation for allocation may overflow High

This operation, which is used in an
allocation
, involves a
potentially large value
and might overflow.
This operation, which is used in an
allocation
, involves a
potentially large value
and might overflow.
This operation, which is used in an
allocation
, involves a
potentially large value
and might overflow.
This operation, which is used in an
allocation
, involves a
potentially large value
and might overflow.

Check failure on line 110 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.
This path depends on a
user-provided value
.

Check failure on line 128 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.
This path depends on a
user-provided value
.

Check failure on line 136 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.
This path depends on a
user-provided value
.

Check failure on line 170 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.
This path depends on a
user-provided value
.

Check failure on line 178 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.
This path depends on a
user-provided value
.

Check failure on line 222 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.

Check failure on line 226 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.

Check failure on line 240 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.

Check failure on line 245 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.

Check failure on line 250 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.

Check failure on line 265 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.

Check failure on line 281 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.

Check failure on line 286 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.

Check failure on line 288 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.

Check failure on line 467 in backend/infra/filesvc/service.go

See this annotation in the file changed.

Code scanning / CodeQL

Uncontrolled data used in path expression High

This path depends on a
user-provided value
.