• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

tinyhttp / tinyhttp / 24465570117
100%

Build:
DEFAULT BRANCH: master
Ran 15 Apr 2026 04:19PM UTC
Jobs 3
Files 44
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

15 Apr 2026 04:19PM UTC coverage: 98.89% (+0.002%) from 98.888%
24465570117

push

github

web-flow
Fix potential XSS in `res.redirect` (#498)

* fix: harden redirect location handling

Avoid encoding the authority portion of absolute redirect URLs.

Stop rendering redirect targets as HTML links in res.redirect.

This prevents allowlist bypasses and removes the XSS-prone href sink.

* chore: changeset

* fix: exclude # from authority match in setLocationHeader and fix typo

Also adds regression test for fragment encoding.

994 of 1015 branches covered (97.93%)

Branch coverage included in aggregate %.

5 of 5 new or added lines in 2 files covered. (100.0%)

1323 of 1328 relevant lines covered (99.62%)

258.31 hits per line

Jobs
ID Job ID Ran Files Coverage
1 24465570117.1 15 Apr 2026 04:19PM UTC 44
98.89
GitHub Action Run
2 24465570117.2 15 Apr 2026 04:19PM UTC 44
98.89
GitHub Action Run
3 24465570117.3 15 Apr 2026 04:19PM UTC 44
98.89
GitHub Action Run
Source Files on build 24465570117
  • Tree
  • List 44
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • 29a4c871 on github
  • Prev Build on master (#24459846409)
  • Next Build on master (#24465684552)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc