Skip to content

feat(smus): Migrate private model from sdk v2 to sdk v3 - GlueCatalog…

20a5e85
Select commit
Loading
Failed to load commit list.
Merged

Merge master into feature/ui-e2e-tests #7884

feat(smus): Migrate private model from sdk v2 to sdk v3 - GlueCatalog…
20a5e85
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL failed Dec 10, 2025 in 2s

9 new alerts including 8 high severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 8 high
  • 1 medium

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 245 in .github/workflows/node.js.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check failure on line 170 in packages/core/src/auth/auth.ts

See this annotation in the file changed.

Code scanning / CodeQL

Polynomial regular expression used on uncontrolled data High

This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '#'.

Check failure on line 52 in packages/core/src/awsService/sagemaker/detached-server/routes/getSession.ts

See this annotation in the file changed.

Code scanning / CodeQL

Use of externally-controlled format string High

Format string depends on a
user-provided value
.

Check failure on line 31 in packages/core/src/codewhisperer/util/importAdderUtil.ts

See this annotation in the file changed.

Code scanning / CodeQL

Polynomial regular expression used on uncontrolled data High

This
regular expression
that depends on
library input
may run slow on strings with many repetitions of ' '.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of ' '.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of ' '.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of ' '.

Check failure on line 65 in packages/core/src/codewhisperer/util/importAdderUtil.ts

See this annotation in the file changed.

Code scanning / CodeQL

Polynomial regular expression used on uncontrolled data High

This
regular expression
that depends on
library input
may run slow on strings starting with '=require(' and with many repetitions of '=require(!'.
This
regular expression
that depends on
library input
may run slow on strings starting with '=require(' and with many repetitions of '=require(!'.
This
regular expression
that depends on
library input
may run slow on strings starting with '=require(' and with many repetitions of '=require(!'.
This
regular expression
that depends on
library input
may run slow on strings starting with '=require(' and with many repetitions of '=require(!'.

Check failure on line 559 in packages/core/src/sagemakerunifiedstudio/explorer/nodes/s3Strategy.ts

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High

This replaces only the first occurrence of '*'.

Check failure on line 94 in packages/core/src/shared/utilities/proxyUtil.ts

See this annotation in the file changed.

Code scanning / CodeQL

Disabling certificate validation High

Disabling certificate validation is strongly discouraged.

Check failure on line 56 in packages/core/src/shared/utilities/textUtilities.ts

See this annotation in the file changed.

Code scanning / CodeQL

Polynomial regular expression used on uncontrolled data High

This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.

Check failure on line 58 in packages/core/src/shared/utilities/textUtilities.ts

See this annotation in the file changed.

Code scanning / CodeQL

Polynomial regular expression used on uncontrolled data High

This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '\n'.

Check failure on line 52 in packages/core/src/test/shared/extensions/ssh.test.ts

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete string escaping or encoding High test

This replaces only the first occurrence of '"'.