Skip to content

ci(security): integrate Bright CI pipeline for security tests and remediation#889

Open
tssbox wants to merge 24 commits intofixer/fix_workflow_tc05from
bright/becac4c0-0a85-4f48-85bb-f5d2e03f3efc
Open

ci(security): integrate Bright CI pipeline for security tests and remediation#889
tssbox wants to merge 24 commits intofixer/fix_workflow_tc05from
bright/becac4c0-0a85-4f48-85bb-f5d2e03f3efc

Conversation

@tssbox
Copy link
Contributor

@tssbox tssbox commented Feb 13, 2026

Note

Fixed 2 of 2 vulnerabilities.
Please review the fixes before merging.

Fix Vulnerability Endpoint Affected Files Resolution
[Critical] XPATH Injection GET /api/partners/searchPartners src/partners/partners.service.ts Implement a more secure input filtering approach and ensure XPath queries are constructed safely.
[Critical] XPATH Injection GET /api/partners/partnerLogin src/partners/partners.service.ts Implemented namespace usage in XPath queries to prevent injection by ensuring queries are executed in a controlled context.
Workflow execution details
  • Repository Analysis: TypeScript, NestJS
  • Entrypoints Discovery: 3 entrypoints found
  • Attack Vectors Identification
  • E2E Security Tests Generation
  • E2E Security Tests Execution: 2 vulnerabilities found
  • Cleanup Irrelevant Test Files: 1 test files removed
  • Applying Security Fixes: 2 fixes applied
  • E2E Security Tests Execution: 2 vulnerabilities found
  • Cleanup Irrelevant Test Files: 0 test files removed
  • Applying Security Fixes: 2 fixes applied
  • E2E Security Tests Execution: 2 vulnerabilities found
  • Cleanup Irrelevant Test Files: 0 test files removed
  • Applying Security Fixes: 2 fixes applied
  • E2E Security Tests Execution: 2 vulnerabilities found
  • Cleanup Irrelevant Test Files: 0 test files removed
  • Applying Security Fixes: 2 fixes applied
  • E2E Security Tests Execution: 0 vulnerabilities found
  • Cleanup Irrelevant Test Files: 2 test files removed
  • ⏭️ Applying Security Fixes: Skipped
  • Workflow Wrap-Up

skip-checks:true
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Comments