@lingo.dev/_compiler@0.12.9
lingodotdev/lingo.dev@lingo.dev/_compiler@0.12.9Jun 22, 2026by github-actions[bot]
AI Summary
A security hardening release addressing high-severity CodeQL findings by improving URL sanitization logic and removing dead code in XML loaders.
Key Highlights
- Improved org-id git-remote parsing to use exact host/subdomain matching instead of substring checks.
- Removed a dead newline replacement in the XML loader to clear CodeQL findings.
- Fixed js/incomplete-url-substring-sanitization and js/incomplete-sanitization issues.
Full Release Notes
### Patch Changes
- [#2134](https://github.com/lingodotdev/lingo.dev/pull/2134) [`e18811f`](https://github.com/lingodotdev/lingo.dev/commit/e18811febc17473ab3a1c695dff2adf154a7344d) Thanks [@cherkanovart](https://github.com/cherkanovart)! - Resolve high-severity CodeQL code-scanning findings (security hardening):
- `org-id` git-remote parsing now extracts the URL host and matches the platform by exact host or subdomain suffix (`host === "github.com" || host.endsWith(".github.com")`, etc.) instead of a substring `includes()` check. This fixes `js/incomplete-url-substring-sanitization` (cli, compiler, new-compiler) while still recognizing official alt-SSH hosts like `ssh.github.com` / `altssh.gitlab.com` and rejecting look-alikes like `github.com.evil.com`. Platform labels for all real remote forms are preserved.
- Removed a dead `.replace("\n", "")` in the XML loader (an earlier `\s+` collapse already strips newlines), which also clears the `js/incomplete-sanitization` finding there.