Skip to content

Conversation

austenstone
Copy link
Contributor

No description provided.

Copy link

github-actions bot commented May 8, 2024

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails

Scanned Manifest Files

product.price +
"');";

return db.one(q);

Check failure

Code scanning / CodeQL

Database query built from user-controlled sources

This query string depends on a [user-provided value](1). This query string depends on a [user-provided value](2).
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
product.price +
"');";

return db.one(q);

Check failure

Code scanning / SonarCloud

Database queries should not be vulnerable to injection attacks

<!--SONAR_ISSUE_KEY:AY9Z0FzBLuCkwUuu9-uf-->Change this code to not construct SQL queries directly from user-controlled data. <p>See more on <a href="https://sonarcloud.io/project/issues?id=octoaustenstone_vulnerable-node&issues=AY9Z0FzBLuCkwUuu9-uf&open=AY9Z0FzBLuCkwUuu9-uf&pullRequest=12">SonarCloud</a></p>
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone closed this May 8, 2024
@austenstone austenstone reopened this May 8, 2024
@austenstone austenstone reopened this Aug 22, 2024
@austenstone austenstone reopened this Aug 22, 2024
@austenstone austenstone reopened this Aug 22, 2024
Copy link

Quality Gate Failed Quality Gate failed

Failed conditions
E Security Rating on New Code (required ≥ A)

See analysis details on SonarCloud

Catch issues before they fail your Quality Gate with our IDE extension SonarLint

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant