Skip to content

Fix false-positive cleartext storage alert - #5154

Merged
Widthdom merged 1 commit into
mainfrom
fix-code-scanning-3
Aug 22, 2026
Merged

Widthdom merged 1 commit into
mainfrom
fix-code-scanning-3

Conversation

@Widthdom

Copy link
Copy Markdown
Owner

Summary

  • address code scanning alert 3, where CodeQL classified validated Git executable paths as sensitive because internal identifiers contained trusted
  • rename the affected internal and test-only data-flow identifiers to Validated*
  • preserve the existing pinned/validated Git executable behavior and all public status fields

Validation

  • dotnet test tests/CodeIndex.Tests/CodeIndex.Tests.csproj -c Release -p:UseSharedCompilation=false --filter "FullyQualifiedName~GitHelperTests|FullyQualifiedName~HookCommandRunnerTests" (net8.0: 108 passed; net9.0: 56 passed, 48 skipped)
  • dotnet build CodeIndex.sln -c Release -p:UseSharedCompilation=false (0 warnings, 0 errors)
  • dotnet build CodeIndex.sln -p:UseSharedCompilation=false (0 warnings, 0 errors)
  • full Release suite: net9.0 passed 11,282 tests; net8.0 passed 11,760 tests with one unrelated timeout-test flake, which passed on an immediate isolated rerun
  • refreshed and verified the repository index; exact searches for all alert-source identifiers return 0 matches

Documentation and changelog

Not required: this is an internal naming-only change with no user-visible behavior or output change.

Security alert

Addresses https://github.com/Widthdom/CodeIndex/security/code-scanning/3. The alert on main will close after this change is merged and code scanning analyzes the updated default branch.

@Widthdom
Widthdom merged commit ace9bf6 into main Aug 22, 2026
10 checks passed
@Widthdom
Widthdom deleted the fix-code-scanning-3 branch August 22, 2026 16:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant