Conversation
PR #196의 키 블록리스트 가드는 실제 오염은 막지만 CodeQL js/remote-property-injection이 sanitizer로 인식하지 않아 main 재분석 후에도 알림 3건이 열려 있었다(지적 라인만 가드 추가분만큼 이동). - out[key]=... 할당식 속성 쓰기를 제거하고 entries 배열 + Object.fromEntries로 전환 — define-property 의미라 __proto__류 키로도 프로토타입 오염 불가(방어 자체도 더 강함) - 위험 키 제외 필터는 유지, 기존 테스트 12건 그대로 통과
fix(common): 쿼리 파라미터 변환을 fromEntries로 전환해 CodeQL 지적 실질 해소
|
Warning Review limit reached
Next review available in: 24 minutes Limit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?Wait for the limit to reset, then comment An organization admin can change what happens after included review limits in Billing. How do review limits work?CodeRabbit enforces per-developer PR review limits within each organization. For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🩺 NestJS Doctor — 89/100 (Good)진단 279건 (error 0).
architecture / security 상위 항목
|
🧹 knip — dead-code 리포트전체 리포트
|
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
Coverage report
Test suite run success1574 tests passing in 184 suites. Report generated by 🧪jest coverage report action from a6889c7 |
릴리즈 개요
직전 릴리즈(#199)에 포함됐던 CodeQL 수정의 후속 1건을 릴리즈합니다.
develop → main이며, 포함된 변경은 PR #200 하나입니다.
배경
PR #196의 키 블록리스트 가드는 실제 오염은 막지만, main 재분석 결과 CodeQL
js/remote-property-injection이 이를 sanitizer로 인식하지 않아 알림 3건이 열린 채 유지됐습니다.경고 대상인 할당식 속성 쓰기(
out[key] = ...)를 entries 배열 +Object.fromEntries로 대체해 소스 자체를 제거했습니다.define-property 의미라
__proto__류 키로도 프로토타입을 오염시킬 수 없어 방어도 더 강해집니다.검증