Fix proxyaddress feature for twitter #18
47 new alerts including 16 critical severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 16 critical
- 29 high
- 2 medium
Alerts not introduced by this pull request might have been detected because the code changes were too large.
See annotations below for details.
Annotations
Check failure on line 49 in packages/adapter-qdrant/src/index.ts
Code scanning / CodeQL
Incomplete multi-character sanitization High
, which may cause an HTML element injection vulnerability.
Check failure on line 978 in packages/adapter-sqlite/src/index.ts
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 97 in packages/client-direct/src/api.ts
Code scanning / CodeQL
Missing rate limiting High
, but is not rate-limited.
Check failure on line 242 in packages/client-direct/src/api.ts
Code scanning / CodeQL
Missing rate limiting High
, but is not rate-limited.
Check failure on line 110 in packages/client-eliza-home/__tests__/services/smart_things_api.test.ts
Code scanning / CodeQL
Hard-coded credentials Critical test
.
Check failure on line 125 in packages/client-eliza-home/__tests__/services/smart_things_api.test.ts
Code scanning / CodeQL
Hard-coded credentials Critical test
.
Check failure on line 143 in packages/client-eliza-home/__tests__/services/smart_things_api.test.ts
Code scanning / CodeQL
Hard-coded credentials Critical test
.
Check failure on line 177 in packages/client-eliza-home/__tests__/services/smart_things_api.test.ts
Code scanning / CodeQL
Hard-coded credentials Critical test
.
Check failure on line 192 in packages/client-eliza-home/__tests__/services/smart_things_api.test.ts
Code scanning / CodeQL
Hard-coded credentials Critical test
.
Check failure on line 214 in packages/client-eliza-home/__tests__/services/smart_things_api.test.ts
Code scanning / CodeQL
Hard-coded credentials Critical test
.
Check failure on line 228 in packages/client-eliza-home/__tests__/services/smart_things_api.test.ts
Code scanning / CodeQL
Hard-coded credentials Critical test
.
Check failure on line 227 in packages/client-slack/src/index.ts
Code scanning / CodeQL
Reflected cross-site scripting High
.
Check failure on line 198 in packages/client-slack/src/messages.ts
Code scanning / CodeQL
Server-side request forgery Critical
of this request depends on a .
Check failure on line 53 in packages/core/__tests__/embedding.test.ts
Code scanning / CodeQL
Hard-coded credentials Critical test
.
Check failure on line 105 in packages/core/src/context.ts
Code scanning / CodeQL
Code injection Critical
.
Check failure on line 1454 in packages/core/src/generation.ts
Code scanning / CodeQL
Hard-coded credentials Critical
.
Check failure on line 2193 in packages/core/src/generation.ts
Code scanning / CodeQL
Hard-coded credentials Critical
.
Check failure on line 133 in packages/core/src/knowledge.ts
Code scanning / CodeQL
Incomplete multi-character sanitization High
, which may cause an HTML element injection vulnerability.
Check failure on line 25 in packages/core/src/parsing.ts
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 23 in packages/core/src/parsing.ts
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 89 in packages/core/src/parsing.ts
Code scanning / CodeQL
Polynomial regular expression used on uncontrolled data High
that depends on may run slow on strings starting with 'json\n' and with many repetitions of 'json\na'.
Check failure on line 108 in packages/core/src/parsing.ts
Code scanning / CodeQL
Polynomial regular expression used on uncontrolled data High
that depends on may run slow on strings starting with '["' and with many repetitions of '["a'.
Check failure on line 146 in packages/core/src/parsing.ts
Code scanning / CodeQL
Polynomial regular expression used on uncontrolled data High
that depends on may run slow on strings starting with 'json\n' and with many repetitions of 'json\na'.
Check failure on line 239 in packages/core/src/parsing.ts
Code scanning / CodeQL
Polynomial regular expression used on uncontrolled data High
that depends on may run slow on strings with many repetitions of ' '.
Check failure on line 136 in packages/core/src/ragknowledge.ts
Code scanning / CodeQL
Incomplete multi-character sanitization High
, which may cause an HTML element injection vulnerability.