Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix autofill signing #13229

Draft
wants to merge 37 commits into
base: main
Choose a base branch
from
Draft

Fix autofill signing #13229

wants to merge 37 commits into from

Conversation

nathan-livefront
Copy link
Collaborator

🎟️ Tracking

📔 Objective

📸 Screenshots

⏰ Reminders before review

  • Contributor guidelines followed
  • All formatters and local linters executed and passed
  • Written new unit and / or integration tests where applicable
  • Protected functional changes with optionality (feature flags)
  • Used internationalization (i18n) for all UI strings
  • CI builds passed
  • Communicated to DevOps any deployment requirements
  • Updated any necessary documentation (Confluence, contributing docs) or informed the documentation team

🦮 Reviewer guidelines

  • 👍 (:+1:) or similar for great changes
  • 📝 (:memo:) or ℹ️ (:information_source:) for notes or general info
  • ❓ (:question:) for questions
  • 🤔 (:thinking:) or 💭 (:thought_balloon:) for more open inquiry that's not quite a confirmed issue and could potentially benefit from discussion
  • 🎨 (:art:) for suggestions / improvements
  • ❌ (:x:) or ⚠️ (:warning:) for more significant problems or concerns needing attention
  • 🌱 (:seedling:) or ♻️ (:recycle:) for future improvements or indications of technical debt
  • ⛏ (:pick:) for minor or nitpick changes

Copy link
Contributor

github-actions bot commented Feb 3, 2025

Logo
Checkmarx One – Scan Summary & Details332d3d0c-aa92-4d51-9b43-c93886257916

New Issues (8)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
CRITICAL CVE-2025-24964 Npm-vitest-3.0.4 Vulnerable Package
CRITICAL CVE-2025-25200 Npm-koa-2.15.3 Vulnerable Package
HIGH CVE-2024-21538 Npm-cross-spawn-7.0.3 Vulnerable Package
MEDIUM Cx877cf216-175c Npm-event-pubsub-4.3.0 Vulnerable Package
MEDIUM Cx8ef77360-5422 Npm-node-ipc-9.2.1 Vulnerable Package
MEDIUM Cx949f3fb2-a0e5 Npm-js-message-1.0.7 Vulnerable Package
MEDIUM Cxafe14174-3b5a Npm-easy-stack-1.0.1 Vulnerable Package
MEDIUM Cxf62a1409-bb90 Npm-js-queue-2.0.2 Vulnerable Package
Fixed Issues (2)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
HIGH Client_DOM_XSS /apps/web/src/connectors/sso.ts: 30
HIGH Client_DOM_XSS /apps/web/src/connectors/sso.ts: 28

Copy link

codecov bot commented Feb 3, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 35.82%. Comparing base (7984bb3) to head (81f7ede).
Report is 132 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff             @@
##             main   #13229       +/-   ##
===========================================
+ Coverage   15.76%   35.82%   +20.06%     
===========================================
  Files          27     3167     +3140     
  Lines        1884    93407    +91523     
  Branches        0    16999    +16999     
===========================================
+ Hits          297    33464    +33167     
- Misses       1587    57352    +55765     
- Partials        0     2591     +2591     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@nathan-livefront nathan-livefront force-pushed the nathan/fix-autofill-signing branch from ed8a313 to f93811e Compare February 3, 2025 20:03
@nathan-livefront nathan-livefront force-pushed the nathan/fix-autofill-signing branch from f93811e to e233142 Compare February 3, 2025 20:28
@nathan-livefront nathan-livefront force-pushed the nathan/fix-autofill-signing branch from ae9f22d to b51e497 Compare February 6, 2025 16:17
@nathan-livefront nathan-livefront force-pushed the nathan/fix-autofill-signing branch from e5f6dc7 to cdb2d4c Compare February 6, 2025 16:33
@nathan-livefront nathan-livefront force-pushed the nathan/fix-autofill-signing branch 2 times, most recently from 91381ab to 06ca190 Compare February 11, 2025 18:24
@nathan-livefront nathan-livefront force-pushed the nathan/fix-autofill-signing branch from 06ca190 to b9ab48e Compare February 11, 2025 20:26
@nathan-livefront nathan-livefront force-pushed the nathan/fix-autofill-signing branch from 1e58770 to aff115a Compare February 11, 2025 22:33
@nathan-livefront nathan-livefront force-pushed the nathan/fix-autofill-signing branch from e79d1bb to a21365f Compare February 12, 2025 21:10
@nathan-livefront nathan-livefront force-pushed the nathan/fix-autofill-signing branch from cbc1fe4 to d568d64 Compare February 12, 2025 22:01
@nathan-livefront nathan-livefront force-pushed the nathan/fix-autofill-signing branch from 0d2f125 to cd2e55d Compare February 13, 2025 19:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants