Skip to content

fix: resolve remaining CodeQL security alerts

86d8f70
Select commit
Loading
Failed to load commit list.
Merged

feat: enhance Figma integration with full API property coverage #251

fix: resolve remaining CodeQL security alerts
86d8f70
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Feb 25, 2026 in 3s

7 new alerts including 7 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 7 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 460 in src/commands/run.ts

See this annotation in the file changed.

Code scanning / CodeQL

Network data written to file Medium

Write to file system depends on
Untrusted data
.

Check warning on line 499 in src/commands/run.ts

See this annotation in the file changed.

Code scanning / CodeQL

Network data written to file Medium

Write to file system depends on
Untrusted data
.

Check warning on line 536 in src/commands/run.ts

See this annotation in the file changed.

Code scanning / CodeQL

Network data written to file Medium

Write to file system depends on
Untrusted data
.

Check warning on line 576 in src/commands/run.ts

See this annotation in the file changed.

Code scanning / CodeQL

Network data written to file Medium

Write to file system depends on
Untrusted data
.

Check warning on line 740 in src/integrations/figma/source.ts

See this annotation in the file changed.

Code scanning / CodeQL

Network data written to file Medium

Write to file system depends on
Untrusted data
.

Check warning on line 776 in src/integrations/figma/source.ts

See this annotation in the file changed.

Code scanning / CodeQL

File data in outbound network request Medium

Outbound network request depends on
file data
.
Outbound network request depends on
file data
.
Outbound network request depends on file data.

Check warning on line 777 in src/integrations/figma/source.ts

See this annotation in the file changed.

Code scanning / CodeQL

File data in outbound network request Medium

Outbound network request depends on
file data
.