From 45298893300492469a6edd1fb53add962c9c0f34 Mon Sep 17 00:00:00 2001 From: Hector Hernandez <39923391+hectorhdzg@users.noreply.github.com> Date: Thu, 1 Oct 2026 15:06:26 -0700 Subject: [PATCH 1/3] Fix debug dashboard security vulnerabilities Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .github/workflows/lock.yml | 3 +-- .../src/components/helpers.ts | 26 ++++++------------- tools/chrome-debug-extension/src/helpers.ts | 26 ++++++------------- 3 files changed, 17 insertions(+), 38 deletions(-) diff --git a/.github/workflows/lock.yml b/.github/workflows/lock.yml index 09eafbd70..399a6472a 100644 --- a/.github/workflows/lock.yml +++ b/.github/workflows/lock.yml @@ -5,9 +5,8 @@ on: - cron: '0 0 * * *' permissions: - actions: write + contents: read issues: write - pull-requests: write jobs: action: diff --git a/extensions/applicationinsights-debugplugin-js/src/components/helpers.ts b/extensions/applicationinsights-debugplugin-js/src/components/helpers.ts index 9e5d58c85..2c3bb1d74 100644 --- a/extensions/applicationinsights-debugplugin-js/src/components/helpers.ts +++ b/extensions/applicationinsights-debugplugin-js/src/components/helpers.ts @@ -66,16 +66,6 @@ export function traverseAndReplace(target: Object, maxDepth: number, currentDept return out; } -function _sanitizeText(value: string) { - if (value) { - value = value.replace(/&/g, "&"); - value = value.replace(/>/g, ">"); - value = value.replace(/" + - _sanitizeText(theText.substring(matchPos, matchPos + matchLen)) + - "" + - theText.substring(matchPos + matchLen); - - elm.innerHTML = innerHtml; + let matchSpan = document.createElement("span"); + matchSpan.className = "matched-text-filter"; + matchSpan.innerText = theText.substring(matchPos, matchPos + matchLen); + + elm.innerText = ""; + elm.appendChild(document.createTextNode(theText.substring(0, matchPos))); + elm.appendChild(matchSpan); + elm.appendChild(document.createTextNode(theText.substring(matchPos + matchLen))); return true; } diff --git a/tools/chrome-debug-extension/src/helpers.ts b/tools/chrome-debug-extension/src/helpers.ts index 6bad7e65f..7d827b029 100644 --- a/tools/chrome-debug-extension/src/helpers.ts +++ b/tools/chrome-debug-extension/src/helpers.ts @@ -68,16 +68,6 @@ export function traverseAndReplace(target: Object, maxDepth: number, currentDept return out; } -function _sanitizeText(value: string) { - if (value) { - value = value.replace(/&/g, "&"); - value = value.replace(/>/g, ">"); - value = value.replace(/" + - _sanitizeText(theText.substring(matchPos, matchPos + matchLen)) + - "" + - theText.substring(matchPos + matchLen); - - elm.innerHTML = innerHtml; + let matchSpan = document.createElement("span"); + matchSpan.className = "matched-text-filter"; + matchSpan.innerText = theText.substring(matchPos, matchPos + matchLen); + + elm.innerText = ""; + elm.appendChild(document.createTextNode(theText.substring(0, matchPos))); + elm.appendChild(matchSpan); + elm.appendChild(document.createTextNode(theText.substring(matchPos + matchLen))); return true; } From 296ba0f491e8ea66a15f6c53f057b8664620c426 Mon Sep 17 00:00:00 2001 From: Hector Hernandez <39923391+hectorhdzg@users.noreply.github.com> Date: Thu, 1 Oct 2026 15:09:15 -0700 Subject: [PATCH 2/3] Revert "Fix debug dashboard security vulnerabilities" This reverts commit 45298893300492469a6edd1fb53add962c9c0f34. --- .github/workflows/lock.yml | 3 ++- .../src/components/helpers.ts | 26 +++++++++++++------ tools/chrome-debug-extension/src/helpers.ts | 26 +++++++++++++------ 3 files changed, 38 insertions(+), 17 deletions(-) diff --git a/.github/workflows/lock.yml b/.github/workflows/lock.yml index 399a6472a..09eafbd70 100644 --- a/.github/workflows/lock.yml +++ b/.github/workflows/lock.yml @@ -5,8 +5,9 @@ on: - cron: '0 0 * * *' permissions: - contents: read + actions: write issues: write + pull-requests: write jobs: action: diff --git a/extensions/applicationinsights-debugplugin-js/src/components/helpers.ts b/extensions/applicationinsights-debugplugin-js/src/components/helpers.ts index 2c3bb1d74..9e5d58c85 100644 --- a/extensions/applicationinsights-debugplugin-js/src/components/helpers.ts +++ b/extensions/applicationinsights-debugplugin-js/src/components/helpers.ts @@ -66,6 +66,16 @@ export function traverseAndReplace(target: Object, maxDepth: number, currentDept return out; } +function _sanitizeText(value: string) { + if (value) { + value = value.replace(/&/g, "&"); + value = value.replace(/>/g, ">"); + value = value.replace(/" + + _sanitizeText(theText.substring(matchPos, matchPos + matchLen)) + + "" + + theText.substring(matchPos + matchLen); + + elm.innerHTML = innerHtml; return true; } diff --git a/tools/chrome-debug-extension/src/helpers.ts b/tools/chrome-debug-extension/src/helpers.ts index 7d827b029..6bad7e65f 100644 --- a/tools/chrome-debug-extension/src/helpers.ts +++ b/tools/chrome-debug-extension/src/helpers.ts @@ -68,6 +68,16 @@ export function traverseAndReplace(target: Object, maxDepth: number, currentDept return out; } +function _sanitizeText(value: string) { + if (value) { + value = value.replace(/&/g, "&"); + value = value.replace(/>/g, ">"); + value = value.replace(/" + + _sanitizeText(theText.substring(matchPos, matchPos + matchLen)) + + "" + + theText.substring(matchPos + matchLen); + + elm.innerHTML = innerHtml; return true; } From 1a7c8c714bb2c9cb102406cfea7b6946ae4bf4e6 Mon Sep 17 00:00:00 2001 From: Hector Hernandez <39923391+hectorhdzg@users.noreply.github.com> Date: Thu, 1 Oct 2026 15:13:58 -0700 Subject: [PATCH 3/3] Update vulnerable transitive dependencies Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- common/config/rush/pnpm-config.json | 9 +++--- common/config/rush/pnpm-lock.yaml | 49 +++++++++++++++-------------- package.json | 10 +++--- 3 files changed, 35 insertions(+), 33 deletions(-) diff --git a/common/config/rush/pnpm-config.json b/common/config/rush/pnpm-config.json index 911e2218c..24b9203c3 100644 --- a/common/config/rush/pnpm-config.json +++ b/common/config/rush/pnpm-config.json @@ -13,12 +13,13 @@ "markdown-it": ">=14.2.0", "decode-uri-component": ">=0.5.0", "@microsoft/api-extractor": "7.58.7", - "brace-expansion": ">=5.0.9 <6.0.0", + "basic-ftp": ">=6.2.1", + "brace-expansion": ">=5.0.12 <6.0.0", "extract-zip": "npm:@electron-internal/extract-zip@^1.0.5", - "fast-uri": ">=3.1.5", - "ip-address": ">=10.4.0", + "fast-uri": ">=4.1.5", + "ip-address": ">=10.7.1", "linkify-it": ">=5.0.2", - "morgan": ">=1.11.0" + "morgan": ">=1.12.1" }, "globalPeerDependencyRules": { "allowAny": ["*"] diff --git a/common/config/rush/pnpm-lock.yaml b/common/config/rush/pnpm-lock.yaml index 62e1cc8f2..a4d203be9 100644 --- a/common/config/rush/pnpm-lock.yaml +++ b/common/config/rush/pnpm-lock.yaml @@ -17,12 +17,13 @@ overrides: markdown-it: '>=14.2.0' decode-uri-component: '>=0.5.0' '@microsoft/api-extractor': 7.58.7 - brace-expansion: '>=5.0.9 <6.0.0' + basic-ftp: '>=6.2.1' + brace-expansion: '>=5.0.12 <6.0.0' extract-zip: npm:@electron-internal/extract-zip@^1.0.5 - fast-uri: '>=3.1.5' - ip-address: '>=10.4.0' + fast-uri: '>=4.1.5' + ip-address: '>=10.7.1' linkify-it: '>=5.0.2' - morgan: '>=1.11.0' + morgan: '>=1.12.1' pnpmfileChecksum: sha256-E1T7OJ3DLTjpDqf4RdJzK9VDtAxgm4gDEQCLYdHD8nI= @@ -946,8 +947,8 @@ packages: resolution: {integrity: sha512-NF+epuEdnUYVlGuhaxbbq+dvJttwLnGY+YixlXlME5KpQ5W3CnXA5cVTneY3SPbPDRkcjMbifrwmFYcClgOZeg==} engines: {node: '>= 0.8'} - basic-ftp@5.3.1: - resolution: {integrity: sha512-bopVNp6ugyA150DDuZfPFdt1KZ5a94ZDiwX4hMgZDzF+GttD80lEy8kj98kbyhLXnPvhtIo93mdnLIjpCAeeOw==} + basic-ftp@6.2.1: + resolution: {integrity: sha512-bK67isD+lKq46AU8vNtjvMaT2ZqAOAmNCbxUHlFBRD4k15NWxyEjmaKtZPlgce58So4BNTjITGQOVTjL9y0ECA==} engines: {node: '>=10.0.0'} batch@0.6.1: @@ -956,8 +957,8 @@ packages: bl@4.1.0: resolution: {integrity: sha512-1W07cM9gS6DcLperZfFSj+bWLtaPGSOHWhPiGzXmvVJbRLdG82sH/Kn8EtW1VqWVA54AKf2h5k5BbnIbwF3h6w==} - brace-expansion@5.0.9: - resolution: {integrity: sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==} + brace-expansion@5.0.12: + resolution: {integrity: sha512-YovQ3rzhaLMIrDjNDMkNS01tea93qhEhG5xy8f6+R0l+dw3Ki+5sCoIoI942iuLZTHWogWktgwVDhU09iNEimQ==} engines: {node: 20 || >=22} braces@3.0.3: @@ -1341,8 +1342,8 @@ packages: fast-levenshtein@2.0.6: resolution: {integrity: sha512-DCXu6Ifhqcks7TZKY3Hxp3y6qphY5SJZmrWMDrKcERSOXWQdMhU9Ig/PYrzyw/ul9jOIyh0N4M0tbC5hodg8dw==} - fast-uri@4.1.4: - resolution: {integrity: sha512-dODXrIxlS9JSdgAnhIUKOosKV1oMtU2VtVw87QRaHzyl5jxO290Ii5tEZfCfzfWNHi3jKWwBSdQj0qIyshdZdQ==} + fast-uri@4.1.5: + resolution: {integrity: sha512-vZeoMRB4epNr7QfdHxel7te/RcX16CxyXI07JCCTFWZA2s4v1azGNESRj+2EoaHSaWFL/Z3GmKT2jF6A202jLg==} fastq@1.20.3: resolution: {integrity: sha512-XKv5nnLs6nLF71NgiKJLIZFLkPyIEuOselLG7ujZnGrRfQK8HpvY+WqKhAJUAdLomwVHErVS4LfxFlPq0/FTAw==} @@ -1637,8 +1638,8 @@ packages: interpret@1.1.0: resolution: {integrity: sha512-CLM8SNMDu7C5psFCn6Wg/tgpj/bKAg7hc2gWqcuR9OD5Ft9PhBpIu8PLicPeis+xDd6YX2ncI8MCA64I9tftIA==} - ip-address@10.7.0: - resolution: {integrity: sha512-BGFsyJd5mpXp3rK6jIdADLNgpJUK1jnjzvYF8lK+VyDab9JAmqN0YOKDdP17HlgKb2+ehPgDc8EtnRLbGCAMhA==} + ip-address@10.7.1: + resolution: {integrity: sha512-4OUAqU9Z1i3vCnS05hzGiFnEMDpQ+62pAD/MVQOp83fYyNC8GleCqaS0QikQBmcWCrKFiUs/B8ztRRiYOAXuCA==} engines: {node: '>= 12'} is-absolute@1.0.0: @@ -1918,8 +1919,8 @@ packages: mitt@3.0.1: resolution: {integrity: sha512-vKivATfr97l2/QBCYAkXYDbrIWPM2IIKEl7YPhjCvKlG3kE2gm+uBo6nEXK3M5/Ffh/FLpKExzOQ3JJoJGFKBw==} - morgan@1.12.0: - resolution: {integrity: sha512-OHpTRQwn2ezasILW8iKe+Yww1XsfWsZIpUOLF7RDb2g5GwO3trPaRwi7+8BDiJ7HFx2Kg2mfUdCBcVhwYlOz2g==} + morgan@1.12.1: + resolution: {integrity: sha512-tljKC0ex20AjO58Ob/eZ53JloycbVswbVNCHx6V6VLGzqt/w8dIynVGL0G8qVjNKwiA7sYSogCrN6QtJ82IV+g==} engines: {node: '>= 0.8.0'} ms@2.0.0: @@ -4102,7 +4103,7 @@ snapshots: ajv@8.18.0: dependencies: fast-deep-equal: 3.1.3 - fast-uri: 4.1.4 + fast-uri: 4.1.5 json-schema-traverse: 1.0.0 require-from-string: 2.0.2 @@ -4227,7 +4228,7 @@ snapshots: dependencies: safe-buffer: 5.1.2 - basic-ftp@5.3.1: {} + basic-ftp@6.2.1: {} batch@0.6.1: {} @@ -4237,7 +4238,7 @@ snapshots: inherits: 2.0.4 readable-stream: 3.6.2 - brace-expansion@5.0.9: + brace-expansion@5.0.12: dependencies: balanced-match: 4.0.4 @@ -4606,7 +4607,7 @@ snapshots: fast-levenshtein@2.0.6: {} - fast-uri@4.1.4: {} + fast-uri@4.1.5: {} fastq@1.20.3: dependencies: @@ -4743,7 +4744,7 @@ snapshots: get-uri@6.0.5: dependencies: - basic-ftp: 5.3.1 + basic-ftp: 6.2.1 data-uri-to-buffer: 6.0.2 debug: 4.4.3 transitivePeerDependencies: @@ -4827,7 +4828,7 @@ snapshots: connect: 3.7.0 connect-livereload: 0.6.1 http2-wrapper: 2.2.1 - morgan: 1.12.0 + morgan: 1.12.1 open: 8.4.2 portscanner: 2.2.0 serve-index: 1.9.2 @@ -4991,7 +4992,7 @@ snapshots: interpret@1.1.0: {} - ip-address@10.7.0: {} + ip-address@10.7.1: {} is-absolute@1.0.0: dependencies: @@ -5244,13 +5245,13 @@ snapshots: minimatch@10.2.6: dependencies: - brace-expansion: 5.0.9 + brace-expansion: 5.0.12 minipass@7.1.3: {} mitt@3.0.1: {} - morgan@1.12.0: + morgan@1.12.1: dependencies: basic-auth: 2.0.1 debug: 2.6.9 @@ -5727,7 +5728,7 @@ snapshots: socks@2.8.10: dependencies: - ip-address: 10.7.0 + ip-address: 10.7.1 smart-buffer: 4.2.0 source-map-resolve@0.6.0: diff --git a/package.json b/package.json index b46c8c787..df1e20cf9 100644 --- a/package.json +++ b/package.json @@ -78,7 +78,7 @@ "@types/node": "18.19.121" }, "overrides": { - "basic-ftp": ">=5.2.0", + "basic-ftp": ">=6.2.1", "form-data": "^2.5.5", "tar": ">=7.5.22", "glob": "^7.2.3", @@ -89,16 +89,16 @@ }, "@microsoft/api-extractor": "7.58.7", "decode-uri-component": ">=0.5.0", - "brace-expansion": "^5.0.9", + "brace-expansion": "^5.0.12", "extract-zip": "npm:@electron-internal/extract-zip@^1.0.5", "linkify-it": "^5.0.2", "markdown-it": "^14.2.0", "yaml": "^2.9.0", "js-yaml": "^4.3.1", "fast-xml-parser": ">=5.10.1", - "fast-uri": ">=3.1.5", - "ip-address": ">=10.4.0", - "morgan": "^1.11.0", + "fast-uri": ">=4.1.5", + "ip-address": ">=10.7.1", + "morgan": "^1.12.1", "grunt": { "js-yaml": "^3.15.1" }