Repository navigation
Conversation
Automated security fix generated by OrbisAI Security Signed-off-by: anupamme <mediratta@gmail.com>
|
these data come from the GitHub API, so there’s no risk, and this doesn’t add anything new to the workflow. |
|
I'm pretty sure that I recognise the OrbitAI Security bot - I have closed multiple bad PRs with this signature (in other repos). In case there's a human who reads this: Has this bot ever detected something correctly? Do you think that using a bot to report nonexistent vulnerabilities with no human oversight and ignoring all policies and guidelines of projects the you try to "contribute" to is in any way ethical? |
|
There is a human in the loop. Sorry for the noise. We do have a decent merge rate in the PRs we open. You can find out about the PRs which get merged here. Coming to the PR, I agree that Would you like to opt out of any future security PRs? |
The template/js/index.js fetches JSON data from external sources (labeledIssues.json, userActivity.json, projects.json) and renders values directly into the DOM using lit-html templates. While lit-html provides auto-escaping for text content, URL values in href attributes and data flows from untrusted external sources lack validation or sanitization. This is defence-in-depth at
template/js/index.js:18rather than a vulnerability I can show is exploitable here — it makes the failure mode explicit and bounded. Close it freely if the pattern is intentional.Reference: CWE-79
What changed
template/js/index.jsVerification
No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.
Automated security fix by OrbisAI Security