Skip to content

fix(ui): keep digest disclosure panels and 24px targets (v0.86.3) - #158

Closed
cursor[bot] wants to merge 123 commits into
mainfrom
cursor/bc-495842fe-64d1-49dd-9f4a-dc6e42a2f830-e7a2
Closed

cursor[bot] wants to merge 123 commits into
mainfrom
cursor/bc-495842fe-64d1-49dd-9f4a-dc6e42a2f830-e7a2

fix(ui): type the pending-detail query as HTMLElement

7726621
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Semgrep OSS succeeded Aug 16, 2026 in 5s

4 new alerts

New alerts in code changed by this pull request

  • 4 warnings

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 211 in backend/app/analysis_run_ingestion.py

See this annotation in the file changed.

Code scanning / Semgrep OSS

Semgrep Finding: python.lang.security.audit.sqli.asyncpg-sqli.asyncpg-sqli Warning

Detected string concatenation with a non-literal variable in a asyncpg Python SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can create parameterized queries like so: 'conn.fetch("SELECT """Au FROM table", value)'. You can also create prepared statements with 'Connection.prepare': 'stmt = conn.prepare("SELECT """Au FROM table"); await stmt.fetch(user_value)'

Check warning on line 211 in backend/app/analysis_run_ingestion.py

See this annotation in the file changed.

Code scanning / Semgrep OSS

Semgrep Finding: python.lang.security.audit.sqli.asyncpg-sqli.asyncpg-sqli Warning

Detected string concatenation with a non-literal variable in a asyncpg Python SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can create parameterized queries like so: 'conn.fetch("SELECT $1 FROM table", value)'. You can also create prepared statements with 'Connection.prepare': 'stmt = conn.prepare("SELECT $1 FROM table"); await stmt.fetch(user_value)'

Check warning on line 229 in backend/app/analysis_run_ingestion.py

See this annotation in the file changed.

Code scanning / Semgrep OSS

Semgrep Finding: python.lang.security.audit.sqli.asyncpg-sqli.asyncpg-sqli Warning

Detected string concatenation with a non-literal variable in a asyncpg Python SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can create parameterized queries like so: 'conn.fetch("SELECT """Au FROM table", value)'. You can also create prepared statements with 'Connection.prepare': 'stmt = conn.prepare("SELECT """Au FROM table"); await stmt.fetch(user_value)'

Check warning on line 229 in backend/app/analysis_run_ingestion.py

See this annotation in the file changed.

Code scanning / Semgrep OSS

Semgrep Finding: python.lang.security.audit.sqli.asyncpg-sqli.asyncpg-sqli Warning

Detected string concatenation with a non-literal variable in a asyncpg Python SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can create parameterized queries like so: 'conn.fetch("SELECT $1 FROM table", value)'. You can also create prepared statements with 'Connection.prepare': 'stmt = conn.prepare("SELECT $1 FROM table"); await stmt.fetch(user_value)'