Skip to content

fix: resolve all 8 CodeQL code scanning alerts - #26

Closed
Kristof Roomp (mcroomp) wants to merge 5 commits into
mainfrom
fix/codeql-alerts
Closed

Kristof Roomp (mcroomp) wants to merge 5 commits into
mainfrom
fix/codeql-alerts

Conversation

@mcroomp

Copy link
Copy Markdown
Contributor

Summary

  • indexserver/api.py — Real security fix: validate that the absolute path reconstructed from a Typesense-sourced relative path is within the configured source root before passing it to os.path.isfile. Uses os.path.realpath to catch ../-style traversal attempts.
  • indexserver/indexer.py (×4), verifier.py (×1), index_queue.py (×1) — # lgtm[py/path-injection] suppressions on false-positive alerts where paths are generated internally by os.walk over a trusted configured root and never derive from external input.
  • tests/test_e2e_modes.py — # lgtm[py/clear-text-storage-sensitive-data] suppression on a hardcoded, test-only API key ("smoke-test-key") that is not a real secret.

Closes all 8 open Code Scanning alerts (alerts #1–#8).

Test plan

  • CodeQL re-scan passes with 0 open alerts after merge
  • Existing unit tests pass: node run_tests.mjs --wsl tests/test_query_cs.py

🤖 Generated with Claude Code

- api.py: add realpath-based path-traversal guard before using Typesense-
  sourced relative paths in filesystem operations (genuine security fix)
- indexer.py, verifier.py, index_queue.py: add lgtm suppressions for
  py/path-injection false positives where paths are generated internally
  by os.walk over a trusted configured root and never come from user input
- test_e2e_modes.py: add lgtm suppression for py/clear-text-storage-
  sensitive-data false positive on a hardcoded test-only API key

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Comment thread indexserver/index_queue.py Fixed
Comment thread indexserver/verifier.py Fixed
Comment thread tests/test_e2e_modes.py Dismissed
Kristof Roomp (mcroomp) and others added 2 commits April 25, 2026 05:45
…ed in path expression'

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…ed in path expression'

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Comment thread indexserver/verifier.py Fixed
…ed in path expression'

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Comment thread indexserver/api.py Fixed
Comment thread indexserver/api.py Fixed
Co-authored-by: Copilot Autofix powered by AI <223894421+github-code-quality[bot]@users.noreply.github.com>
@mcroomp
Kristof Roomp (mcroomp) deleted the fix/codeql-alerts branch April 30, 2026 12:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants