Skip to content
This repository was archived by the owner on Oct 1, 2026. It is now read-only.

[CTX-0083] fix(codeql): resolve remaining code scanning alerts - #147

Merged
Xuepoo merged 4 commits into
mainfrom
fix/codeql-remaining-alerts
Sep 27, 2026
Merged

Xuepoo merged 4 commits into
mainfrom
fix/codeql-remaining-alerts

Conversation

@Xuepoo

@Xuepoo Xuepoo commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Resolve remaining CodeQL alerts:

All tests pass:

683 pass
0 fail

Local gates: just check (fmt, lint, type-check, bun test, cargo test)
green.

Closes code scanning alerts #2 (aka #6 after renumbering), #3, #4

Priority: P1 | Area: ci | Labels: fix,P1,area:devtools | Milestone: v0.1.0 | RFC: - | Task: CTX-0083

- Alert #5: Remove useless assignment to baselineTerminals/baselineViews
- Alert #3: Remove unused SocketDirStat import

Fixes: 2 of 4 CodeQL alerts
Comment thread tests/workflow-import.test.ts Fixed
#6)

statSync(path).isFile() ? readFileSync(path) : undefined still checks
then uses the same path, so CodeQL js/file-system-race (alert #6,
severity high) still flagged it after the prior existsSync ->
statSync change. Read directly and treat any read failure (ENOENT,
race, wrong type) as "no content" via try/catch, matching CodeQL's
own recommended fix and the file-log/config helpers already using
this pattern earlier in the same file.

Priority: P1 | Area: ci | Labels: fix,P1,area:ci | Milestone: v0.1.0 | RFC: - | Task: CTX-0083
@Xuepoo Xuepoo added fix Bug fix P1 Priority P1 labels Sep 27, 2026
@Xuepoo Xuepoo added this to the v0.1.0 milestone Sep 27, 2026
@Xuepoo Xuepoo changed the title fix(codeql): resolve remaining code scanning alerts [CTX-0083] fix(codeql): resolve remaining code scanning alerts Sep 27, 2026
@Xuepoo Xuepoo added the area:devtools devtools area label Sep 27, 2026
- Remove unused 'rmdirSync' import (alert #4)
- Fix file-system-race (TOCTOU) alerts by replacing existsSync checks with try-catch:
  - Directory existence check before readdirSync
  - File existence checks before copyFileSync (4 locations)
  - File existence check before appendFileSync
- All local checks pass: just check, type-check, fmt-check, test
@Xuepoo
Xuepoo merged commit d036975 into main Sep 27, 2026
9 checks passed
@Xuepoo
Xuepoo deleted the fix/codeql-remaining-alerts branch September 27, 2026 06:41
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area:devtools devtools area fix Bug fix P1 Priority P1

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants