Repository navigation
test(ci): exact-line assert in grok-build config test (CodeQL #740/#741) - #7628
Merged
Merged
Conversation
CodeQL js/incomplete-url-substring-sanitization (HIGH) flags
content.includes("https://example.test/v1") in the grok-build config
preservation test as a URL-substring check. It's a false positive — a
test asserting a TOML section round-trips, not URL sanitization — but it
is the only pair of open CodeQL alerts repo-wide, so check:codeql-ratchet
keeps Quality Ratchet red on every open PR.
Replace the two URL-substring checks with exact line membership
(content.split + Array.includes on the full 'base_url = "..."' line).
Stronger (verifies the URL is on the base_url key, not merely present)
and no longer a substring-of-URL sink. All 9 tests pass.
Contributor
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
Owner
Author
|
Verified — the two CodeQL alerts (#740/#741) map exactly to lines 146 and 203 in this file, and the exact-line assertion is strictly stronger than the old substring check (it pins the URL to the |
HouMinXi
pushed a commit
to HouMinXi/OmniRoute
that referenced
this pull request
Aug 2, 2026
…uzapw#740/diegosouzapw#741) (diegosouzapw#7628) Validated in local merge-train @ 8f27177d1 (full parity suite green: typecheck+file-size+complexity+cognitive+changelog+unit shards 1&2+vitest)
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…uzapw#740/diegosouzapw#741) (diegosouzapw#7628) Validated in local merge-train @ 8f27177d1 (full parity suite green: typecheck+file-size+complexity+cognitive+changelog+unit shards 1&2+vitest)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Replaces two URL-substring assertions in
tests/integration/cli-settings-grok-build.test.ts(lines 146 & 203) with exact line membership.Why
CodeQL
js/incomplete-url-substring-sanitization(HIGH) flagscontent.includes("https://example.test/v1")as a URL-substring check. It's a false positive — the test asserts a TOML[model.custom-thing]section round-trips untouched through the grok-build config handler; there is no URL sanitization andexample.testis a reserved test TLD.But #740 + #741 are the only open CodeQL alerts repo-wide right now (they replaced #737 the moment it closed), and
check:codeql-ratchetcounts alerts repo-wide → they keepQuality Ratchetred on every open PR. This closes them at the source.Fix
Exact line membership is stronger than the old substring check — it verifies the URL sits on the
base_urlkey, not merely somewhere in the file — and is no longer a substring-of-URL sink, so CodeQL stops flagging it. The handler preserves the section byte-for-byte, so exact match holds.Validation (Hard Rule #18)
node --import tsx/esm --test tests/integration/cli-settings-grok-build.test.ts→ 9 pass, 0 fail.File exists only on
release/v3.8.49(added by #7241) — nomaincompanion needed.