Skip to content

fix: Dependabot Friday schedule and CodeQL alert #1 - #38

Merged
RealDougEubanks merged 1 commit into
mainfrom
fix/dependabot-schedule-codeql-alert
Sep 10, 2026
Merged

RealDougEubanks merged 1 commit into
mainfrom
fix/dependabot-schedule-codeql-alert

Conversation

@RealDougEubanks

Copy link
Copy Markdown
Owner

Summary

  • Dependabot schedule: both ecosystems (github-actions, docker) now run weekly on Friday at 08:00 America/New_York instead of the GitHub default (Monday, random UTC time). Adds day, time, and timezone to both entries in dependabot.yml.

  • CodeQL alert Phase 1 MVP: GitHub backup, hardened Docker, tests, CI #1 (py/incomplete-url-substring-sanitization): CodeQL flagged test_keeps_scheme_and_host in tests/test_webserver.py for using startswith('https://hooks.slack.com') — a pattern it flags as incomplete URL sanitization. This is a false positive: the check is a test assertion on the output of _redact_url(), not a sanitization guard. The production code uses urlsplit() correctly. Fixed by replacing the imprecise startswith assertion with an exact assertEqual against the full expected output ('https://hooks.slack.com/…[redacted]'), which is both more precise and no longer triggers the rule.

Test plan

🤖 Generated with Claude Code

https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5

Dependabot: add day/time/timezone to both ecosystems so scans run
Friday at 08:00 America/New_York instead of the default (Monday, random
time UTC).

CodeQL alert #1 (py/incomplete-url-substring-sanitization): CodeQL
flagged test_keeps_scheme_and_host for using startswith() against a URL
string, which it treats as an incomplete sanitization pattern. The
production _redact_url() already uses urlsplit() correctly; the test
assertion was simply imprecise. Replace startswith() with assertEqual()
against the exact expected output — tighter test, no CodeQL flag.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@RealDougEubanks
RealDougEubanks merged commit 70c6997 into main Sep 10, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant