Skip to content

CodeQL Alert #2 - Security rule js/incomplete-url-substring-sanitization triggered #524

Open
@jwj019

Description

@jwj019

Tool: CodeQL (2.13.4)
Rule: js/incomplete-url-substring-sanitization
Severity: warning (Security level: high)
Description: Incomplete URL substring sanitization
Instance reference: refs/heads/main
Instance state: open
Location: dist/index.js @ l24204:c7-l24204:c73
Message: 's3.amazonaws.com' can be anywhere in the URL, and arbitrary hosts may come before or after it.

CodeQL Alert Link

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions