chore(deps): bump @tiptap/extension-table from 3.30.1 to 3.30.2 in /sdk/typescript - #34
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@tiptap/extension-table](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-table) from 3.30.1 to 3.30.2. - [Release notes](https://github.com/ueberdosis/tiptap/releases) - [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/extension-table/CHANGELOG.md) - [Commits](https://github.com/ueberdosis/tiptap/commits/v3.30.2/packages/extension-table) --- updated-dependencies: - dependency-name: "@tiptap/extension-table" dependency-version: 3.30.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
mmlong818
deleted the
dependabot/npm_and_yarn/sdk/typescript/tiptap/extension-table-3.30.2
branch
September 4, 2026 18:14
Contributor
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
mmlong818
added a commit
that referenced
this pull request
Sep 11, 2026
11 条告警在 2026-09-11 被批量标记成 false positive。逐条读过代码之后,其中三条确实是 误报,四条不是: 真误报(维持驳回): - #42 model-scheduler.ts:createHmac 用的是每进程 randomBytes(32) 盐,只做连接池 key 且不落盘,代码注释已写明意图; - #35 data-sync.ts:sha256 算的是密文做完整性校验,口令走的是 scryptSync; - #44 workbench-ui.js:route.href 来自应用自己注入的 ClownfishProductStructure, 不是 DOM 读入的外部输入。 以下四条是真的: #43 server.ts 连接指纹。原先是 sha256 覆盖 {provider, protocol, baseUrl, apiKey}, 并把结果写进任务 payload 落进 agent-jobs.json。四个字段里三个是公开可知的,等于给 apiKey 留了个可离线验证的摘要。指纹要回答的只是「连接变没变」,而 connectionRevision 本来就在这四项任一变化时铸新 UUID——语义等价且完全不碰密钥。同一个仓库里 model-scheduler.ts 早就用每进程 HMAC 盐避开了同一问题,这里的标准本来就该一致。 行为影响:改之前入队的任务,其 payload 里存的是旧的 sha256,比对必然不等,会走 「连接已改变,不会把共享材料发送到另一服务」这条既有拒绝路径——是安全方向,且正是 model-cross-entry 测试覆盖的那条路径。 #38 scramble-wallpaper.js 只转义了引号没转义反斜杠,值又被拼进 url("...")。以反斜杠 结尾的壁纸地址会把闭合引号转义掉从而逃逸成 CSS。壁纸地址用户可设。改为先转义反斜杠 再转义引号,并丢掉在 CSS 字符串里非法的控制字符。 #34 office-workbench.js 的 /^(\s*#\s*)+$/ 是嵌套量词,输入是用户文档正文。实测: 把它喂给 " # ".repeat(24) + "!",超过 199 秒没有返回。段落此前已 trim 且非空, 换成线性的 [#\s]+ 判定等价。 #32/#33 ui-evidence.ts:& 排在 < 前面解码,会把 &lt; 二次解码成真的 <; 剥标签的正则不认 </script > 这种带尾随空白的闭合标签,脚本正文会被当正文留下。 & 挪到最后解,闭合标签允许尾随空白。 测试在 tests/unit/companion-codeql-fixes.test.ts,每条都验证过「撤掉修复就会失败」: 撤掉前三处 → 4 条失败;把 & 解码挪回最前 → 对应那条失败。 ReDoS 那条最初写成了跑构造输入加超时断言,实测会让测试进程挂死 199 秒而不是快速失败 (同步正则没法从同一线程里掐断),已改成断言正则形状,构造输入留在注释里。 为可测把 ui-evidence.ts 的 textOf 导出——剥标签与实体解码的顺序值得直接对行为下断言, 而不是只断言正则长什么样。 npm run check 通过(919 项测试 918 通过、0 失败、1 跳过)。
mmlong818
added a commit
that referenced
this pull request
Sep 25, 2026
11 条告警在 2026-09-11 被批量标记成 false positive。逐条读过代码之后,其中三条确实是 误报,四条不是: 真误报(维持驳回): - #42 model-scheduler.ts:createHmac 用的是每进程 randomBytes(32) 盐,只做连接池 key 且不落盘,代码注释已写明意图; - #35 data-sync.ts:sha256 算的是密文做完整性校验,口令走的是 scryptSync; - #44 workbench-ui.js:route.href 来自应用自己注入的 ClownfishProductStructure, 不是 DOM 读入的外部输入。 以下四条是真的: #43 server.ts 连接指纹。原先是 sha256 覆盖 {provider, protocol, baseUrl, apiKey}, 并把结果写进任务 payload 落进 agent-jobs.json。四个字段里三个是公开可知的,等于给 apiKey 留了个可离线验证的摘要。指纹要回答的只是「连接变没变」,而 connectionRevision 本来就在这四项任一变化时铸新 UUID——语义等价且完全不碰密钥。同一个仓库里 model-scheduler.ts 早就用每进程 HMAC 盐避开了同一问题,这里的标准本来就该一致。 行为影响:改之前入队的任务,其 payload 里存的是旧的 sha256,比对必然不等,会走 「连接已改变,不会把共享材料发送到另一服务」这条既有拒绝路径——是安全方向,且正是 model-cross-entry 测试覆盖的那条路径。 #38 scramble-wallpaper.js 只转义了引号没转义反斜杠,值又被拼进 url("...")。以反斜杠 结尾的壁纸地址会把闭合引号转义掉从而逃逸成 CSS。壁纸地址用户可设。改为先转义反斜杠 再转义引号,并丢掉在 CSS 字符串里非法的控制字符。 #34 office-workbench.js 的 /^(\s*#\s*)+$/ 是嵌套量词,输入是用户文档正文。实测: 把它喂给 " # ".repeat(24) + "!",超过 199 秒没有返回。段落此前已 trim 且非空, 换成线性的 [#\s]+ 判定等价。 #32/#33 ui-evidence.ts:& 排在 < 前面解码,会把 &lt; 二次解码成真的 <; 剥标签的正则不认 </script > 这种带尾随空白的闭合标签,脚本正文会被当正文留下。 & 挪到最后解,闭合标签允许尾随空白。 测试在 tests/unit/companion-codeql-fixes.test.ts,每条都验证过「撤掉修复就会失败」: 撤掉前三处 → 4 条失败;把 & 解码挪回最前 → 对应那条失败。 ReDoS 那条最初写成了跑构造输入加超时断言,实测会让测试进程挂死 199 秒而不是快速失败 (同步正则没法从同一线程里掐断),已改成断言正则形状,构造输入留在注释里。 为可测把 ui-evidence.ts 的 textOf 导出——剥标签与实体解码的顺序值得直接对行为下断言, 而不是只断言正则长什么样。 npm run check 通过(919 项测试 918 通过、0 失败、1 跳过)。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps @tiptap/extension-table from 3.30.1 to 3.30.2.
Release notes
Sourced from @tiptap/extension-table's releases.
Changelog
Sourced from @tiptap/extension-table's changelog.
Commits
cef2c9achore(release): release new stable release (#8190)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)