Skip to content

Security fixes from codeQL alerts#203

Merged
tcezard merged 3 commits into
EBIvariation:masterfrom
tcezard:security_fixes
May 22, 2026
Merged

Security fixes from codeQL alerts#203
tcezard merged 3 commits into
EBIvariation:masterfrom
tcezard:security_fixes

Conversation

@tcezard

@tcezard tcezard commented May 21, 2026

Copy link
Copy Markdown
Member
  1. SSRF: Added SAFE_CONTIG_PATTERN and validateContigIdentifier() guard in all 4 URL-building methods
  2. Error exposure: Replaced e.getMessage() with "Request parameters exceed allowed limits" or "Invalid request parameters"
  3. Permissions: Added permissions: contents: read block in github actions

@tcezard tcezard requested review from apriltuesday and nitin-ebi May 22, 2026 07:35
@tcezard tcezard merged commit f100839 into EBIvariation:master May 22, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants