Skip to content

fix(security): clear new CodeQL code-scanning alerts (round 4) - #11293

Merged
diegosouzapw merged 1 commit into
release/v3.8.50from
fix/codeql-alerts-v3850-round4
Aug 23, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.50from
fix/codeql-alerts-v3850-round4

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Summary

Closes the 2 new CodeQL code-scanning alerts:

  • js/insecure-randomness — open-sse/executors/github.ts:344: the Copilot correlation-id generators (x-request-id, x-interaction-id, x-client-session-id, x-agent-task-id) fell back to Math.random() when crypto.randomUUID is unavailable. Replaced with a CSPRNG-backed randomIdFallback() (node:crypto randomBytes) — no behavior change, crypto.randomUUID stays the primary path.
  • js/double-escaping — tests/unit/cli/_helpers/shellArgs.mjs:27: unescapeWindowsShellArg() chained two sequential global .replace() unescape passes, which lets the first pass's output feed the second — the exact double-(un)escaping bug pattern the query flags (an escaped-backslash-then-quote sequence could be misread depending on pass order). Collapsed into a single left-to-right regex replace with alternation.

Test plan

  • node --import tsx/esm --test tests/unit/cli/run-command.test.ts — 12/12 pass
  • node --import tsx/esm --test tests/unit/executor-github.test.ts tests/unit/8951-github-gpt56-responses.test.ts tests/unit/github-copilot-custom-model-target-format.test.ts tests/unit/github-copilot-claude-native-messages.test.ts tests/unit/executor-github-prefill-sanitize.test.ts tests/unit/copilot-claude-always-v1-messages.test.ts tests/unit/copilot-gemini-claude-route-no-responses.test.ts tests/unit/t27-github-copilot-response-format.test.ts — 62/62 pass
  • npx eslint on changed files — no new errors (pre-existing no-explicit-any violations in github.ts are frozen/suppressed, unrelated to this change)

⚠️ base-red inherited: #9985

- open-sse/executors/github.ts: replace the Math.random() fallback in
  the Copilot correlation-id generators (x-request-id,
  x-interaction-id, x-client-session-id, x-agent-task-id) with a
  CSPRNG-backed randomIdFallback() (node:crypto randomBytes) — closes
  js/insecure-randomness with no behavior change (crypto.randomUUID
  stays the primary path).
- tests/unit/cli/_helpers/shellArgs.mjs: collapse the two sequential
  global .replace() unescape passes into a single left-to-right regex
  replace with alternation — closes js/double-escaping. The prior
  two-pass form let the first pass's output feed the second, which is
  exactly the double-(un)escaping bug pattern the query flags (e.g. an
  escaped-backslash-then-quote sequence could be misread depending on
  pass order).
@diegosouzapw
diegosouzapw merged commit 2904cf8 into release/v3.8.50 Aug 23, 2026
13 of 22 checks passed
@diegosouzapw
diegosouzapw deleted the fix/codeql-alerts-v3850-round4 branch August 25, 2026 02:36
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…souzapw#11293)

- open-sse/executors/github.ts: replace the Math.random() fallback in
  the Copilot correlation-id generators (x-request-id,
  x-interaction-id, x-client-session-id, x-agent-task-id) with a
  CSPRNG-backed randomIdFallback() (node:crypto randomBytes) — closes
  js/insecure-randomness with no behavior change (crypto.randomUUID
  stays the primary path).
- tests/unit/cli/_helpers/shellArgs.mjs: collapse the two sequential
  global .replace() unescape passes into a single left-to-right regex
  replace with alternation — closes js/double-escaping. The prior
  two-pass form let the first pass's output feed the second, which is
  exactly the double-(un)escaping bug pattern the query flags (e.g. an
  escaped-backslash-then-quote sequence could be misread depending on
  pass order).

Co-authored-by: Markus Hartung <mail@hartmark.se>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants