Skip to content

Fix dashboard DOM XSS findings - #73

Closed
MIpetrov-NI wants to merge 3 commits into
mainfrom
agents/dependabot-config-setup-guide
Closed

MIpetrov-NI wants to merge 3 commits into
mainfrom
agents/dependabot-config-setup-guide

Conversation

@MIpetrov-NI

@MIpetrov-NI MIpetrov-NI commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • remediate high-severity CodeQL DOM XSS findings in dashboard configuration, update-progress, and shared-header flows
  • replace HTML-string status/progress rendering with DOM nodes and text content
  • constrain generated workflow and revision navigation targets to safe encoded or validated values
  • synchronize all affected .github/pages and bundled actions/dashboard assets

Validation

  • exercised dashboard pages with markup-like repository values and verified text-only status output plus encoded GitHub workflow URLs
  • verified all affected canonical/bundled page pairs are byte-identical
  • git diff --check

Replace HTML-string rendering in dashboard status and progress flows with safe DOM nodes, validate generated navigation URLs, and keep the canonical and bundled page copies synchronized.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@MIpetrov-NI
MIpetrov-NI requested a review from elijah286 as a code owner October 1, 2026 22:31
const showDashLink = () => {
const dl = $("insDashLink");
if (dl) { dl.href = url; dl.innerHTML = "Open your dashboard &#8599;"; dl.style.display = ""; }
if (dl) { dl.href = url; dl.textContent = "Open your dashboard \u2197"; dl.style.display = ""; }
const showDashLink = () => {
const dl = $("insDashLink");
if (dl) { dl.href = url; dl.innerHTML = "Open your dashboard &#8599;"; dl.style.display = ""; }
if (dl) { dl.href = url; dl.textContent = "Open your dashboard \u2197"; dl.style.display = ""; }
Build dynamic installation-summary list items with DOM nodes instead of HTML strings so setup values remain text.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
location.id = "insLiveUrl";
if (live) {
const link = document.createElement("a");
link.href = url;
location.id = "insLiveUrl";
if (live) {
const link = document.createElement("a");
link.href = url;
@MIpetrov-NI MIpetrov-NI closed this Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants