Files
OmniRoute/scripts
rafaumeu 0056dbc3b5 fix(security): silence CodeQL js/incomplete-url-substring-sanitization in aliasResolver (#7808)
CodeQL flagged bin/aliasResolver.mjs for building a
`data:text/javascript,...` URL dynamically via `new URL()` to register the
ESM loader hook — flagged as js/incomplete-url-substring-sanitization.

Refactor: extract the hook source into a real file
`bin/aliasResolverHook.mjs` and load it via `pathToFileURL()` from
`node:url` instead of the inline data-URL approach. The hook behaviour is
unchanged (still resolves `@/<path>` specifiers relative to the repo root
passed via the register `data` option).

Supporting changes so CI stays green:
- pack-artifact-policy.ts: add bin/aliasResolver.mjs and
  bin/aliasResolverHook.mjs to both ALLOWED_EXACT_PATHS (tarball ship) and
  REQUIRED_PATHS (regression guard — absence now fails loudly).
- tests/unit/pack-artifact-policy.test.ts: update the
  findMissingArtifactPaths snapshot expectation.
- config/quality/quality-baseline.json: rebaseline bundleSize 6534 -> 6762
  (+228). The hook file is now a 5th bin/*.mjs entrypoint counted by
  size-limit; the bytes were previously hidden inside aliasResolver.mjs
  because the template literal was compressed away.
2026-07-19 23:39:07 -03:00
..
2026-07-13 09:12:40 -03:00
2026-06-29 08:40:06 -03:00
2026-06-23 17:06:18 -03:00
2026-06-19 06:49:01 -03:00
2026-06-23 17:06:18 -03:00
2026-06-29 08:40:06 -03:00
2026-07-13 09:12:40 -03:00
2026-06-17 19:26:32 -03:00
2026-06-27 09:07:12 -03:00
2026-06-27 09:07:12 -03:00
2026-07-13 09:12:40 -03:00
2026-06-04 20:05:38 -03:00
2026-07-13 09:12:40 -03:00