mirror of
https://github.com/openclaw/openclaw.git
synced 2026-05-07 10:30:43 +00:00
Adds a narrow critical-security CodeQL shard for the network/SSRF boundary and documents the new category.
44 lines
899 B
YAML
44 lines
899 B
YAML
name: openclaw-codeql-network-ssrf-boundary-critical-security
|
|
|
|
disable-default-queries: true
|
|
|
|
queries:
|
|
- uses: security-extended
|
|
|
|
query-filters:
|
|
- include:
|
|
precision:
|
|
- high
|
|
- very-high
|
|
- exclude:
|
|
problem.severity:
|
|
- recommendation
|
|
- warning
|
|
|
|
paths:
|
|
- src/infra/net
|
|
- src/shared/net
|
|
- src/agents/tools/web-fetch.ts
|
|
- src/agents/tools/web-guarded-fetch.ts
|
|
- src/agents/tools/web-shared.ts
|
|
- src/plugin-sdk/ssrf-policy.ts
|
|
- src/web-fetch
|
|
- src/web/provider-runtime-shared.ts
|
|
- packages/memory-host-sdk/src/host/ssrf-policy.ts
|
|
|
|
paths-ignore:
|
|
- "**/node_modules"
|
|
- "**/coverage"
|
|
- "**/*.generated.ts"
|
|
- "**/*.bundle.js"
|
|
- "**/*-runtime.js"
|
|
- "**/*.test.ts"
|
|
- "**/*.test.tsx"
|
|
- "**/*.e2e.test.ts"
|
|
- "**/*.e2e.test.tsx"
|
|
- "**/*test-support*"
|
|
- "**/*test-helper*"
|
|
- "**/*mock*"
|
|
- "**/*fixture*"
|
|
- "**/*bench*"
|