fix(language-server): harden _merge for CodeQL prototype-pollution-utility#42
Conversation
…-utility - Skip __proto__, constructor, prototype with literal comparisons - Only deep-merge when key is an own property of target (CodeQL CWE-915 guidance) Made-with: Cursor
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 10 minutes and 7 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Goal
Resolve CodeQL alert
js/prototype-pollution-utilityonpackages/language-server/src/module.ts(_merge, copied from Langium DI).Changes
__proto__,constructor,prototype(matches CodeQL CWE-915 examples).targetviaObject.prototype.hasOwnProperty.call(target, key), so we do not recurse into objects reached only through the prototype chain.References
Verification
pnpm turbo run typecheck --filter=@likec4/language-server --filter=@likec4/language-services