Conversation
CodeQL js/remote-property-injection(high) 3건 반영. toQueryParams가 사용자 쿼리 문자열의 키를 그대로 객체 속성으로 써서 __proto__ 등 위험 키가 속성 이름으로 유입될 수 있었다. - __proto__/constructor/prototype 키는 변환에서 제외 - CodeQL이 sanitizer로 인식하도록 Set이 아닌 명시적 키 비교 사용 - 회귀 테스트 1건 추가
fix(common): 쿼리 키의 프로토타입 오염 위험 속성 쓰기 차단
보류 사유였던 실DB 테스트 인프라 이관이 완료되어(184 suites 전부 testcontainers) 수행 조건을 충족했다. 이슈는 ts-jest 30 동반 필요를 전제했지만 ts-jest 29.4.x가 jest ^30을 peer로 지원해 bump 불필요. - jest ^29 → ^30 (30.4.1), @types/jest ^29 → ^30 - ts-jest는 ^29 유지 (peer: jest ^29 || ^30) - 코드/설정 변경 없이 전체 스위트 통과 (1574 tests / 184 suites)
chore: jest 29 → 30 마이그레이션
TS 6가 출력 레이아웃 기준 디렉터리 명시를 요구(TS5011)해 보류했던 마이그레이션. tsc --noEmit·전체 테스트는 무변경 통과라 실제 조치는 빌드 설정 명시뿐이었다. - typescript ^5.7.3 → ^6.0.3 - typescript-eslint ^8.59.3 → ^8.67.0 (TS <6.1 peer 지원 버전) - tsconfig.build.json에 rootDir ./src 명시 — 기존 공통 소스 디렉터리와 동일해 dist 산출 구조 불변 - 빌드 부산물 *.tsbuildinfo gitignore 추가 (incremental 활성 상태)
chore: TypeScript 5.9 → 6.0 마이그레이션
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (5)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough
Changes쿼리 키 안전성
개발 도구 설정
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to The release filters unsafe query keys and updates development tooling/build configuration without a demonstrated regression; validation and build checks pass, so no actionable merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🧹 knip — dead-code 리포트전체 리포트
|
🩺 NestJS Doctor — 89/100 (Good)진단 279건 (error 0).
architecture / security 상위 항목
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Coverage report
Test suite run success1574 tests passing in 184 suites. Report generated by 🧪jest coverage report action from 3ef2a5c |
릴리즈 개요
CodeQL 보안 수정 1건과 개발 도구 메이저 마이그레이션 2건을 릴리즈합니다.
develop → main이며, 포함된 변경은 PR #196 / #197 / #198 세 건입니다.
런타임 동작 변경은 #196의 쿼리 키 필터링뿐이고, 나머지는 개발 의존성입니다.
포함 변경
js/remote-property-injection(high) 3건 해소:toQueryParams가 사용자 쿼리 키를 그대로 객체 속성으로 쓰던 것을 차단.__proto__/constructor/prototype키는 변환에서 제외합니다.이 릴리즈가 main에 반영되면 CodeQL 재분석 시 알림 3건이 자동 종료될 예정입니다.
ts-jest는 29.4.x가 jest ^30을 peer 지원해 유지했습니다.
tsconfig.build.json의rootDir: "./src"명시로 해소, dist 산출 구조 불변.typescript-eslint를 TS <6.1 peer 지원 버전(8.67)으로 동반 bump.
이 릴리즈로 이슈 #58, #60이 자동 종료됩니다.
검증
yarn validate전체 통과 (1574 tests / 184 suites, 커버리지 게이트 포함).yarn builddist 레이아웃 불변 확인 (chore: TypeScript 5.9 → 6.0 마이그레이션 #198).Summary by CodeRabbit
버그 수정
개선 사항