From 3c35c985a1e29d2f1d70833a9bbadd78c9c7d79f Mon Sep 17 00:00:00 2001 From: Doug Eubanks Date: Wed, 9 Sep 2026 22:42:09 -0400 Subject: [PATCH] fix: schedule Dependabot for Friday 8am ET and resolve CodeQL alert #1 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Dependabot: add day/time/timezone to both ecosystems so scans run Friday at 08:00 America/New_York instead of the default (Monday, random time UTC). CodeQL alert #1 (py/incomplete-url-substring-sanitization): CodeQL flagged test_keeps_scheme_and_host for using startswith() against a URL string, which it treats as an incomplete sanitization pattern. The production _redact_url() already uses urlsplit() correctly; the test assertion was simply imprecise. Replace startswith() with assertEqual() against the exact expected output — tighter test, no CodeQL flag. Co-Authored-By: Claude Sonnet 4.6 Claude-Session: https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5 --- .github/dependabot.yml | 6 ++++++ tests/test_webserver.py | 2 +- 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 8f29fb9..da787ff 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -14,6 +14,9 @@ updates: directory: "/" schedule: interval: "weekly" + day: "friday" + time: "08:00" + timezone: "America/New_York" open-pull-requests-limit: 5 commit-message: prefix: "ci" @@ -23,6 +26,9 @@ updates: directory: "/docker" schedule: interval: "weekly" + day: "friday" + time: "08:00" + timezone: "America/New_York" open-pull-requests-limit: 5 commit-message: prefix: "build" diff --git a/tests/test_webserver.py b/tests/test_webserver.py index 8a2c9a3..0ca6bbd 100644 --- a/tests/test_webserver.py +++ b/tests/test_webserver.py @@ -138,7 +138,7 @@ def test_discord_url_var_redacted(self): class TestRedactUrl(unittest.TestCase): def test_keeps_scheme_and_host(self): out = webserver._redact_url('https://hooks.slack.com/services/secret') - self.assertTrue(out.startswith('https://hooks.slack.com')) + self.assertEqual(out, 'https://hooks.slack.com/…[redacted]') self.assertNotIn('secret', out) def test_non_url_value_redacted(self):