Skip to content

Conversation

@LuoPengcheng12138
Copy link
Collaborator

Description

Scan the project and fix issues using the CodeQL tool.
https://githubdocs.cn/en/code-security/codeql-cli/getting-started-with-the-codeql-cli/about-the-codeql-cli

What is the purpose of this pull request?

  • Bug fix
  • New Feature
  • Documentation update
  • Other

@LuoPengcheng12138
Copy link
Collaborator Author

hi, @Wendong-Fan ,I believe I have fixed all vulnerabilities in the code written by our team. The remaining alerts originate from the compiled artifacts of certain third-party source code: package/@stackframe/react/dist and package/@stackframe/stack-shared/dist.
Scanning vulnerabilities in compiled artifacts seems meaningless. In addition, I have attempted to update react/dist and stack-shared/dist to their latest released versions, yet these alerts still persist. I think this PR has completed all the fixes that can be done at present.

@LuoPengcheng12138 LuoPengcheng12138 requested review from Wendong-Fan, fengju0213 and nitpicker55555 and removed request for Wendong-Fan December 18, 2025 16:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature Request] resolve vulnerabilities detected by security scan

2 participants