mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-26 09:52:11 +03:00
Quality Gate was failing on New Code with 1 hotspot, 1 vulnerability and 4 reliability bugs. Resolved each at the source (no SonarCloud mark-as-safe): Reliability (4 bugs → rating back to A): - usage.ts: drop duplicate `case "opencode-go"` (S1862) — the 2nd case was dead (first match wins) and would have called the wrong usage fetcher. Also de-duplicate the same id in USAGE_FETCHER_PROVIDERS (mirrors the switch; prevented a double quota-fetcher registration). - ApiManagerPageClient.tsx: a dangling `.find(...)?.timestamp || null` expression (S905) discarded the better matcher — `lastUsed` silently lost the name-fallback for legacy logs without apiKeyId. Assign the complete matcher. - chat.ts / auth.ts: `Promise` used in a boolean conditional (S6544). Both are intentional (memoized promise / mutex default), not a forgotten await — made the intent explicit via `!== null` and `??` (behaviour identical). Security (vulnerability → rating back to A): - nvidia-startswith-diag.ts: neutralize CR/LF before logging env-derived values (S5145 log injection) in the ad-hoc diagnostic script. Security Hotspot (reviewed → 0 open): - pluginWorker.ts uses `vm.runInContext` to run plugin code — that IS the worker's purpose, inside a hardened vm sandbox (createContext, require allow-list of just `crypto`, 10s timeout); not eval/new Function. Suppress S1523 scoped only to pluginWorker.ts in sonar-project.properties, with the same documented-justification pattern as the existing hotspot suppressions.