lingo.dev@0.137.3

lingodotdev/lingo.devlingo.dev@0.137.3Jun 22, 2026by github-actions[bot]

AI Summary

A security hardening release addressing high-severity CodeQL findings by improving URL sanitization logic and removing dead code in XML loaders.

Key Highlights

  • Improved org-id git-remote parsing to use exact host/subdomain matching instead of substring checks.
  • Removed a dead newline replacement in the XML loader to clear CodeQL findings.
  • Fixed js/incomplete-url-substring-sanitization and js/incomplete-sanitization issues.

Full Release Notes

### Patch Changes

- [#2134](https://github.com/lingodotdev/lingo.dev/pull/2134) [`e18811f`](https://github.com/lingodotdev/lingo.dev/commit/e18811febc17473ab3a1c695dff2adf154a7344d) Thanks [@cherkanovart](https://github.com/cherkanovart)! - Resolve high-severity CodeQL code-scanning findings (security hardening):
  - `org-id` git-remote parsing now extracts the URL host and matches the platform by exact host or subdomain suffix (`host === "github.com" || host.endsWith(".github.com")`, etc.) instead of a substring `includes()` check. This fixes `js/incomplete-url-substring-sanitization` (cli, compiler, new-compiler) while still recognizing official alt-SSH hosts like `ssh.github.com` / `altssh.gitlab.com` and rejecting look-alikes like `github.com.evil.com`. Platform labels for all real remote forms are preserved.
  - Removed a dead `.replace("\n", "")` in the XML loader (an earlier `\s+` collapse already strips newlines), which also clears the `js/incomplete-sanitization` finding there.

- Updated dependencies [[`e18811f`](https://github.com/lingodotdev/lingo.dev/commit/e18811febc17473ab3a1c695dff2adf154a7344d)]:
  - @lingo.dev/_compiler@0.12.9