Repository navigation
fix(security): clear new CodeQL code-scanning alerts (round 4) - #11293
Merged
Merged
Conversation
- open-sse/executors/github.ts: replace the Math.random() fallback in the Copilot correlation-id generators (x-request-id, x-interaction-id, x-client-session-id, x-agent-task-id) with a CSPRNG-backed randomIdFallback() (node:crypto randomBytes) — closes js/insecure-randomness with no behavior change (crypto.randomUUID stays the primary path). - tests/unit/cli/_helpers/shellArgs.mjs: collapse the two sequential global .replace() unescape passes into a single left-to-right regex replace with alternation — closes js/double-escaping. The prior two-pass form let the first pass's output feed the second, which is exactly the double-(un)escaping bug pattern the query flags (e.g. an escaped-backslash-then-quote sequence could be misread depending on pass order).
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…souzapw#11293) - open-sse/executors/github.ts: replace the Math.random() fallback in the Copilot correlation-id generators (x-request-id, x-interaction-id, x-client-session-id, x-agent-task-id) with a CSPRNG-backed randomIdFallback() (node:crypto randomBytes) — closes js/insecure-randomness with no behavior change (crypto.randomUUID stays the primary path). - tests/unit/cli/_helpers/shellArgs.mjs: collapse the two sequential global .replace() unescape passes into a single left-to-right regex replace with alternation — closes js/double-escaping. The prior two-pass form let the first pass's output feed the second, which is exactly the double-(un)escaping bug pattern the query flags (e.g. an escaped-backslash-then-quote sequence could be misread depending on pass order). Co-authored-by: Markus Hartung <mail@hartmark.se>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes the 2 new CodeQL code-scanning alerts:
open-sse/executors/github.ts:344: the Copilot correlation-id generators (x-request-id,x-interaction-id,x-client-session-id,x-agent-task-id) fell back toMath.random()whencrypto.randomUUIDis unavailable. Replaced with a CSPRNG-backedrandomIdFallback()(node:cryptorandomBytes) — no behavior change,crypto.randomUUIDstays the primary path.tests/unit/cli/_helpers/shellArgs.mjs:27:unescapeWindowsShellArg()chained two sequential global.replace()unescape passes, which lets the first pass's output feed the second — the exact double-(un)escaping bug pattern the query flags (an escaped-backslash-then-quote sequence could be misread depending on pass order). Collapsed into a single left-to-right regex replace with alternation.Test plan
node --import tsx/esm --test tests/unit/cli/run-command.test.ts— 12/12 passnode --import tsx/esm --test tests/unit/executor-github.test.ts tests/unit/8951-github-gpt56-responses.test.ts tests/unit/github-copilot-custom-model-target-format.test.ts tests/unit/github-copilot-claude-native-messages.test.ts tests/unit/executor-github-prefill-sanitize.test.ts tests/unit/copilot-claude-always-v1-messages.test.ts tests/unit/copilot-gemini-claude-route-no-responses.test.ts tests/unit/t27-github-copilot-response-format.test.ts— 62/62 passnpx eslinton changed files — no new errors (pre-existingno-explicit-anyviolations in github.ts are frozen/suppressed, unrelated to this change)