Skip to content

Petrinaut HIR: compile user code to buffer-native programs, remove Babel - #8973

Closed
kube wants to merge 13 commits into
mainfrom
petrinaut-lang
Closed

Petrinaut HIR: compile user code to buffer-native programs, remove Babel#8973
kube wants to merge 13 commits into
mainfrom
petrinaut-lang

feat(petrinaut): harden HIR compilation flow

43b98ea
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Jul 14, 2026 in 3s

3 new alerts including 3 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 3 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 129 in libs/@hashintel/petrinaut-core/src/hir/emit-js.ts

See this annotation in the file changed.

Code scanning / CodeQL

Improper code sanitization Medium

Code construction depends on an
improperly sanitized value
.
Code construction depends on an
improperly sanitized value
.

Check warning on line 167 in libs/@hashintel/petrinaut-core/src/hir/instantiate.ts

See this annotation in the file changed.

Code scanning / CodeQL

Unsafe code constructed from library input Medium

This string concatenation which depends on
library input
is later
interpreted as code
.
This string concatenation which depends on
library input
is later
interpreted as code
.
This string concatenation which depends on
library input
is later
interpreted as code
.
This string concatenation which depends on
library input
is later
interpreted as code
.
This string concatenation which depends on
library input
is later
interpreted as code
.
This string concatenation which depends on library input is later
interpreted as code
.

Check warning on line 225 in libs/@hashintel/petrinaut-core/src/hir/instantiate.ts

See this annotation in the file changed.

Code scanning / CodeQL

Unsafe code constructed from library input Medium

This string concatenation which depends on
library input
is later
interpreted as code
.
This string concatenation which depends on
library input
is later
interpreted as code
.
This string concatenation which depends on
library input
is later
interpreted as code
.
This string concatenation which depends on
library input
is later
interpreted as code
.
This string concatenation which depends on library input is later
interpreted as code
.