Skip to content

Create product#12

Open
austenstone wants to merge 6 commits intomain-enterprisefrom
create-product
Open

Create product#12
austenstone wants to merge 6 commits intomain-enterprisefrom
create-product

Conversation

@austenstone
Copy link
Copy Markdown
Contributor

No description provided.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 8, 2024

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails

Scanned Manifest Files

Comment thread model/products.js
product.price +
"');";

return db.one(q);

Check failure

Code scanning / CodeQL

Database query built from user-controlled sources

This query string depends on a [user-provided value](1). This query string depends on a [user-provided value](2).
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
Comment thread model/products.js
product.price +
"');";

return db.one(q);

Check failure

Code scanning / SonarCloud

Database queries should not be vulnerable to injection attacks

<!--SONAR_ISSUE_KEY:AY9Z0FzBLuCkwUuu9-uf-->Change this code to not construct SQL queries directly from user-controlled data. <p>See more on <a href="https://sonarcloud.io/project/issues?id=octoaustenstone_vulnerable-node&issues=AY9Z0FzBLuCkwUuu9-uf&open=AY9Z0FzBLuCkwUuu9-uf&pullRequest=12">SonarCloud</a></p>
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone reopened this Aug 22, 2024
@austenstone austenstone reopened this Aug 22, 2024
@austenstone austenstone reopened this Aug 22, 2024
@sonarqubecloud
Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
E Security Rating on New Code (required ≥ A)

See analysis details on SonarCloud

Catch issues before they fail your Quality Gate with our IDE extension SonarLint

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants