• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / confur / 32869021940
95%

Build:
DEFAULT BRANCH: main
Ran 25 Aug 2026 03:58PM UTC
Jobs 1
Files 22
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

25 Aug 2026 03:57PM UTC coverage: 94.887%. Remained the same
32869021940

push

github

web-flow
fix(js): use textContent for status text, drop dead confur-client2.js (#68)

* fix(js): use textContent for status text, drop dead confur-client2.js

Semgrep flagged four XSS findings across two files. Neither is exploitable,
but both are worth closing rather than triaging away.

js/confur-client.js:132-133 assigned server data to .innerHTML. The values are
not attacker-controlled - `updated` is current_time('l, Y-m-d h:i:s A') and
`state` is $_POST['submit_answers'] filtered through an in_array() allowlist
before AnswerHandler returns it - so this was never reachable. But both are
plain strings, .textContent is the correct sink for plain strings, and using it
removes the finding class instead of arguing about reachability each time the
scanner runs. No behaviour change.

js/confur-client2.js was byte-identical to confur-client.js and enqueued by
nothing: AssetService registers js/confur-client.js by literal filename, and no
other enqueue or dynamic path construction references it. It was still being
shipped, because build.php bundles js/ wholesale, so a dead 319-line copy went
into every release zip and carried the other two findings with it.

The remaining innerHTML uses in confur-client.js (lines 13-14, 47) are static
markup with no interpolation, which is why Semgrep left them alone.

* fix(js): stage the textContent change (missed in the previous commit)

2264 of 2386 relevant lines covered (94.89%)

4.1 hits per line

Jobs
ID Job ID Ran Files Coverage
1 32869021940.1 25 Aug 2026 03:58PM UTC 22
94.89
GitHub Action Run
Source Files on build 32869021940
  • Tree
  • List 22
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #32869021940
  • 6ce87cc1 on github
  • Prev Build on main (#32069096999)
  • Next Build on main (#32869082362)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc