From 0f08e1e49c180535169198522fcd8b608c8403eb Mon Sep 17 00:00:00 2001
From: Chad Bentz <1760475+felickz@users.noreply.github.com>
Date: Thu, 15 Sep 2022 09:28:01 -0400
Subject: [PATCH 1/2] Update README.md
---
README.md | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/README.md b/README.md
index f36a510..ac018d2 100644
--- a/README.md
+++ b/README.md
@@ -1,6 +1,6 @@
# Code Scanning C# Tutorial
-Welcome to the Code Scanning C# Tutorial! This tutorial will take you through how to set up Github Advanced Security: Code Scanning as well as interpret results that it may find. The following repository contains cross-site scripting vulnerability for demonstration purpose.
+Welcome to the Code Scanning C# Tutorial! This tutorial will take you through how to set up Github Advanced Security: Code Scanning as well as interpret results that it may find. The following repository contains a cross-site scripting vulnerability for demonstration purpose.
## Introduction
@@ -39,7 +39,7 @@ Click `Set up code scanning`.
#### Setup Workflow
-Click the `Setup this workflow` button by CodeQL Analysis.
+Click the `Configure CodeQL alerts` button.
@@ -163,7 +163,7 @@ Click `show paths` in order to see the dataflow path that resulted in this alert
Fix the Security Alert
-In order to fix this specific alert, we will need to ensure the content being write to the `HttpContext`'s response is validated and sanitized.
+In order to fix this specific alert, we will need to ensure the content being written to the `HttpContext`'s response is both validated and sanitized.
Click on the `Code` tab and [Edit](https://docs.github.com/en/free-pro-team@latest/github/managing-files-in-a-repository/editing-files-in-your-repository) the file [`Autocomplete.ashx.cs`](./WebGoat/WebGoatCoins/Autocomplete.ashx.cs) in the `WebGoat/WebGoatCoins` folder. For this demonstration purpose, we will simply write some hardcoded value to the `HttpContext` instance, this granatees the parameter is sanitized and safe.
From fbcaf7b5273a851e285df7363a005eddc2840833 Mon Sep 17 00:00:00 2001
From: Mike
Date: Mon, 14 Nov 2022 08:59:14 +0100
Subject: [PATCH 2/2] Correct programming language java -> C#
---
README.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/README.md b/README.md
index ac018d2..3cbf952 100644
--- a/README.md
+++ b/README.md
@@ -43,7 +43,7 @@ Click the `Configure CodeQL alerts` button.
-This will create a GitHub Actions Workflow file with CodeQL already set up. Since Java is a compiled language you will need to setup the build in later steps. See the [documentation](https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/running-codeql-code-scanning-in-your-ci-system) if you would like to configure CodeQL Analysis with a 3rd party CI system instead of using GitHub Actions.
+This will create a GitHub Actions Workflow file with CodeQL already set up. Since C# is a compiled language you will need to setup the build in later steps. See the [documentation](https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/running-codeql-code-scanning-in-your-ci-system) if you would like to configure CodeQL Analysis with a 3rd party CI system instead of using GitHub Actions.