Skip to content

fix(security): CodeQL findings — email injection, allocation DoS, cookie flags - #13

Merged
Jairus (JairusSW) merged 1 commit into
mainfrom
fix/codeql-hardening
Jul 7, 2026
Merged

fix(security): CodeQL findings — email injection, allocation DoS, cookie flags#13
Jairus (JairusSW) merged 1 commit into
mainfrom
fix/codeql-hardening

Conversation

@JairusSW

@JairusSW JairusSW commented Jul 7, 2026

Copy link
Copy Markdown
Member

Fixes the first-party CodeQL alerts:

build/vet/gofmt clean; both stores compile. (The remaining 4 alerts are js/bad-tag-filter inside the vendored marked library, whose output we always run through DOMPurify — handled separately.)

@JairusSW
Jairus (JairusSW) merged commit 17cf094 into main Jul 7, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant