Skip to content

fix: imported fixes 06-11-26 - #40892

Merged
julio-rocketchat merged 2 commits into
release-8.4.4from
backport-8.4.4-40889
Jun 11, 2026
Merged

fix: imported fixes 06-11-26#40892
julio-rocketchat merged 2 commits into
release-8.4.4from
backport-8.4.4-40889

Conversation

@dionisio-bot

@dionisio-bot dionisio-bot Bot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

Backport of #40889

Co-authored-by: Matheus Cardoso <matheus@cardo.so>
@dionisio-bot
dionisio-bot Bot requested a review from a team as a code owner June 11, 2026 14:22
@dionisio-bot
dionisio-bot Bot requested a review from julio-rocketchat June 11, 2026 14:22
@dionisio-bot dionisio-bot Bot added the backport Used to inform backported PR label Jun 11, 2026
@changeset-bot

changeset-bot Bot commented Jun 11, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: fb1f28b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
Name Type
@rocket.chat/meteor Patch
@rocket.chat/core-typings Patch
@rocket.chat/rest-typings Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@codecov

codecov Bot commented Jun 11, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 88.11189% with 34 lines in your changes missing coverage. Please review.
⚠️ Please upload report for BASE (release-8.4.4@45fd571). Learn more about missing BASE report.

Additional details and impacted files

Impacted file tree graph

@@               Coverage Diff                @@
##             release-8.4.4   #40892   +/-   ##
================================================
  Coverage                 ?   69.96%           
================================================
  Files                    ?     3309           
  Lines                    ?   120933           
  Branches                 ?    21636           
================================================
  Hits                     ?    84606           
  Misses                   ?    33017           
  Partials                 ?     3310           
Flag Coverage Δ
e2e 59.61% <ø> (?)
e2e-api 46.25% <5.55%> (?)
unit 70.73% <89.64%> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@dionisio-bot

dionisio-bot Bot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR is not ready to merge, because of the following issues:

  • This PR is missing the 'stat: QA assured' label
  • This PR is missing the required milestone or project

Please fix the issues and try again

If you have any trouble, please check the PR guidelines

@rc-layne

rc-layne Bot commented Jun 11, 2026

Copy link
Copy Markdown

Warning

These are security findings reported by the security scanners configured in Layne. Findings may contain false positives - review them and fix what makes sense.

Layne found 1 high issue in this PR.

View 1 finding(s)
Severity Scanner File Rule Description
🟠 High semgrep apps/meteor/app/apple/lib/handleIdentityToken.ts:42 app.config.semgrep.rules.rocketchat.ssrf-validation-bypass-without-justification SSRF validation is disabled. Ensure the URL is not user-controlled or is restricted to a known-safe allowlist.

@julio-rocketchat

Copy link
Copy Markdown
Member

/layne exception-approve LAYNE-2ddd92cdd5a7448f reason: hardcoded url

@rc-layne

rc-layne Bot commented Jun 11, 2026

Copy link
Copy Markdown

✅ Exception recorded for LAYNE-2ddd92cdd5a7448f by @julio-rocketchat: "hardcoded url". Re-running scan...

@julio-rocketchat
julio-rocketchat merged commit 230ea91 into release-8.4.4 Jun 11, 2026
115 of 119 checks passed
@julio-rocketchat
julio-rocketchat deleted the backport-8.4.4-40889 branch June 11, 2026 18:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant