Skip to content

security: remediate CodeQL logging and ReDoS alerts - #64

Merged
KIM3310 merged 1 commit into
mainfrom
agent/codeql-remediation-20260810
Aug 10, 2026
Merged

security: remediate CodeQL logging and ReDoS alerts#64
KIM3310 merged 1 commit into
mainfrom
agent/codeql-remediation-20260810

Conversation

@KIM3310

@KIM3310 KIM3310 commented Aug 10, 2026

Copy link
Copy Markdown
Owner

Summary

  • replace the XML-root repair regex with deterministic bounded parsing
  • emit only fixed credential status tokens from Datadog plan/validate/sync output
  • use fixed configuration labels instead of environment-variable identifiers in experiment failure logs
  • add adversarial, credential-sentinel, and missing-configuration regressions

CodeQL alerts addressed

Validation

  • pnpm verify: 190 files / 1,731 tests, check, typecheck, and build
  • coverage: 83.00% statements
  • 13 Python tests and benchmark command
  • repository-surface/health, YAML, gitleaks, and diff checks

@KIM3310
KIM3310 merged commit 93b5b56 into main Aug 10, 2026
16 checks passed
@KIM3310
KIM3310 deleted the agent/codeql-remediation-20260810 branch August 10, 2026 14:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant