Skip to content

Conversation

jeongsoolee09
Copy link
Contributor

@jeongsoolee09 jeongsoolee09 commented Aug 25, 2023

  • Bump MaD (advanced-security/javascript-sap-ui5-extensions) from 0.0.1 to 0.1.0
  • Bump queries (advanced-security/javascript-sap-ui5-queries) from 0.0.1 to 0.1.0
  • State advanced-security/javascript-sap-ui5-extensions as dependency ("^0.1.1") of advanced-security/javascript-sap-ui5-queries so that they can be installed together
  • Match up codeql/javascript-all among the both to "^0.6.3"
  • Exclude js/log-injection, js/missing-x-frame-options, and js/xss, assuming the customer's going to run the default JavaScript query suite along our suite
  • Unify Semver to 0.1.0

@jeongsoolee09 jeongsoolee09 self-assigned this Aug 25, 2023
@jeongsoolee09 jeongsoolee09 changed the title MaD: 1.0.0, queries: 1.0.1 Bump version: 1.0.0 and 1.0.1 Aug 25, 2023
Copy link

@rvermeulen rvermeulen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We still need to make the extension target version explicit and it seems the CodeQL test workflow failed 😿

@mbaluda
Copy link
Contributor

mbaluda commented Aug 30, 2023

@jeongsoolee09 I do not think we should exclude js/missing-x-frame-options, our query is not related to the default one.

@rvermeulen the test issue was there already but now the workflow checks the status and fails accordingly. We can safely ignore it for this PR...

@mbaluda
Copy link
Contributor

mbaluda commented Aug 30, 2023

@jeongsoolee09 did you push everything? The change does not seem to match the description...

@jeongsoolee09
Copy link
Contributor Author

@mbaluda js/missing-x-frame-options catches vanilla JS version of clickjacking.

As they are not included in the first place
Copy link
Contributor

@mbaluda mbaluda left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good to me

Copy link

@rvermeulen rvermeulen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:shipit:

@jeongsoolee09 jeongsoolee09 merged commit be12b48 into main Aug 31, 2023
@jeongsoolee09 jeongsoolee09 deleted the jeongsoolee09/bump-version branch September 11, 2023 21:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants