Skip to content

Bugfixes - #8

Merged
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes
Mar 7, 2026
Merged

Bugfixes#8
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes

Conversation

@Zenith1415

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI review requested due to automatic review settings March 7, 2026 02:09

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the ShieldCI security scanning workflow to support additional triggers and richer metadata, while adding generated scan artifacts under tests/ for reference.

Changes:

  • Expand GitHub Actions triggers (push + manual) and add event-aware metadata output.
  • Adjust workflow steps for config/repo copying, duration output, and PR-only commenting.
  • Add ShieldCI scan output artifacts (shield_results.json, scan_output.log) and a tests/repo subproject pointer.

Reviewed changes

Copilot reviewed 3 out of 5 changed files in this pull request and generated 3 comments.

FileDescription
tests/shield_results.jsonAdds a ShieldCI results JSON artifact including a markdown report payload
tests/scan_output.logAdds a captured ShieldCI orchestrator run log
tests/repoAdds a subproject commit pointer under tests
.github/workflows/shieldci.ymlExtends workflow triggers, metadata gathering, result pushing, and PR commenting logic

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +64 to +65
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The workflow hardcodes an API key (and an API URL) directly in the repository. This exposes credentials to anyone with repo access and to any workflow log/runner that can read the YAML. Move these values back to GitHub Secrets (e.g., secrets.SHIELDCI_API_URL / secrets.SHIELDCI_API_KEY) and avoid committing real keys to source control.

Suggested change
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec
SHIELDCI_API_URL: ${{ secrets.SHIELDCI_API_URL }}
SHIELDCI_API_KEY: ${{ secrets.SHIELDCI_API_KEY }}

Copilot uses AI. Check for mistakes.
SHIELDCI_TRIGGERED_BY: ${{ steps.meta.outputs.trigger }}
SHIELDCI_RESULTS_FILE: ${{ runner.temp }}/../../../Desktop/ShieldCI/tests/shield_results.json
run: |
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SHIELDCI_RESULTS_FILE is set to two different values: one via the job env: (with a brittle runner.temp + ../../../ traversal), then overridden in the step with export. This can lead to confusing behavior depending on which value push_results.py reads and makes the path resolution fragile. Use a single, consistent absolute path for SHIELDCI_RESULTS_FILE (preferably set once in env) and remove the conflicting override.

Suggested change
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

Copilot uses AI. Check for mistakes.
Comment on lines +2 to +3
"status": "Clean",
"vulnerabilities": [],

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This fixture is internally inconsistent: it marks the scan status as Clean and vulnerabilities as an empty list, while report_markdown describes multiple critical vulnerabilities. If downstream logic/tests rely on status/vulnerabilities to match the report, this will produce incorrect behavior. Align the JSON fields with the report content (e.g., non-clean status and populated vulnerabilities) or adjust the report_markdown to match a clean scan.

Suggested change
"status": "Clean",
"vulnerabilities": [],
"status": "Vulnerable",
"vulnerabilities": [
{
"id": "SQL_INJECTION_LOGIN",
"title": "SQL Injection in /login route",
"severity": "critical",
"description": "The GET /login route builds SQL queries via string concatenation using unsanitized user input, allowing SQL injection."
},
{
"id": "INSECURE_PASSWORD_STORAGE",
"title": "Insecure password storage",
"severity": "high",
"description": "Passwords are stored in plaintext instead of being hashed with a secure algorithm such as bcrypt."
},
{
"id": "IDOR_LOGIN",
"title": "Insecure Direct Object Reference in /login",
"severity": "high",
"description": "The /login route does not properly validate or sanitize the username parameter, potentially exposing sensitive user data."
}
],

Copilot uses AI. Check for mistakes.
@Akshat-Raj
Akshat-Raj merged commit 8b9f727 into Akshat-Raj:mainMar 7, 2026
2 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Zenith1415@Akshat-Raj
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Bugfixes by Zenith1415 · Pull Request #8 · Akshat-Raj/ShieldCI · GitHub
Skip to content

Bugfixes - #8

Merged
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes
Mar 7, 2026
Merged

Bugfixes#8
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes

Conversation

@Zenith1415

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI review requested due to automatic review settings March 7, 2026 02:09

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the ShieldCI security scanning workflow to support additional triggers and richer metadata, while adding generated scan artifacts under tests/ for reference.

Changes:

  • Expand GitHub Actions triggers (push + manual) and add event-aware metadata output.
  • Adjust workflow steps for config/repo copying, duration output, and PR-only commenting.
  • Add ShieldCI scan output artifacts (shield_results.json, scan_output.log) and a tests/repo subproject pointer.

Reviewed changes

Copilot reviewed 3 out of 5 changed files in this pull request and generated 3 comments.

FileDescription
tests/shield_results.jsonAdds a ShieldCI results JSON artifact including a markdown report payload
tests/scan_output.logAdds a captured ShieldCI orchestrator run log
tests/repoAdds a subproject commit pointer under tests
.github/workflows/shieldci.ymlExtends workflow triggers, metadata gathering, result pushing, and PR commenting logic

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +64 to +65
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The workflow hardcodes an API key (and an API URL) directly in the repository. This exposes credentials to anyone with repo access and to any workflow log/runner that can read the YAML. Move these values back to GitHub Secrets (e.g., secrets.SHIELDCI_API_URL / secrets.SHIELDCI_API_KEY) and avoid committing real keys to source control.

Suggested change
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec
SHIELDCI_API_URL: ${{ secrets.SHIELDCI_API_URL }}
SHIELDCI_API_KEY: ${{ secrets.SHIELDCI_API_KEY }}

Copilot uses AI. Check for mistakes.
SHIELDCI_TRIGGERED_BY: ${{ steps.meta.outputs.trigger }}
SHIELDCI_RESULTS_FILE: ${{ runner.temp }}/../../../Desktop/ShieldCI/tests/shield_results.json
run: |
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SHIELDCI_RESULTS_FILE is set to two different values: one via the job env: (with a brittle runner.temp + ../../../ traversal), then overridden in the step with export. This can lead to confusing behavior depending on which value push_results.py reads and makes the path resolution fragile. Use a single, consistent absolute path for SHIELDCI_RESULTS_FILE (preferably set once in env) and remove the conflicting override.

Suggested change
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

Copilot uses AI. Check for mistakes.
Comment on lines +2 to +3
"status": "Clean",
"vulnerabilities": [],

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This fixture is internally inconsistent: it marks the scan status as Clean and vulnerabilities as an empty list, while report_markdown describes multiple critical vulnerabilities. If downstream logic/tests rely on status/vulnerabilities to match the report, this will produce incorrect behavior. Align the JSON fields with the report content (e.g., non-clean status and populated vulnerabilities) or adjust the report_markdown to match a clean scan.

Suggested change
"status": "Clean",
"vulnerabilities": [],
"status": "Vulnerable",
"vulnerabilities": [
{
"id": "SQL_INJECTION_LOGIN",
"title": "SQL Injection in /login route",
"severity": "critical",
"description": "The GET /login route builds SQL queries via string concatenation using unsanitized user input, allowing SQL injection."
},
{
"id": "INSECURE_PASSWORD_STORAGE",
"title": "Insecure password storage",
"severity": "high",
"description": "Passwords are stored in plaintext instead of being hashed with a secure algorithm such as bcrypt."
},
{
"id": "IDOR_LOGIN",
"title": "Insecure Direct Object Reference in /login",
"severity": "high",
"description": "The /login route does not properly validate or sanitize the username parameter, potentially exposing sensitive user data."
}
],

Copilot uses AI. Check for mistakes.
@Akshat-Raj
Akshat-Raj merged commit 8b9f727 into Akshat-Raj:mainMar 7, 2026
2 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Zenith1415@Akshat-Raj
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Bugfixes by Zenith1415 · Pull Request #8 · Akshat-Raj/ShieldCI · GitHub
Skip to content

Bugfixes - #8

Merged
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes
Mar 7, 2026
Merged

Bugfixes#8
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes

Conversation

@Zenith1415

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI review requested due to automatic review settings March 7, 2026 02:09

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the ShieldCI security scanning workflow to support additional triggers and richer metadata, while adding generated scan artifacts under tests/ for reference.

Changes:

  • Expand GitHub Actions triggers (push + manual) and add event-aware metadata output.
  • Adjust workflow steps for config/repo copying, duration output, and PR-only commenting.
  • Add ShieldCI scan output artifacts (shield_results.json, scan_output.log) and a tests/repo subproject pointer.

Reviewed changes

Copilot reviewed 3 out of 5 changed files in this pull request and generated 3 comments.

FileDescription
tests/shield_results.jsonAdds a ShieldCI results JSON artifact including a markdown report payload
tests/scan_output.logAdds a captured ShieldCI orchestrator run log
tests/repoAdds a subproject commit pointer under tests
.github/workflows/shieldci.ymlExtends workflow triggers, metadata gathering, result pushing, and PR commenting logic

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +64 to +65
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The workflow hardcodes an API key (and an API URL) directly in the repository. This exposes credentials to anyone with repo access and to any workflow log/runner that can read the YAML. Move these values back to GitHub Secrets (e.g., secrets.SHIELDCI_API_URL / secrets.SHIELDCI_API_KEY) and avoid committing real keys to source control.

Suggested change
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec
SHIELDCI_API_URL: ${{ secrets.SHIELDCI_API_URL }}
SHIELDCI_API_KEY: ${{ secrets.SHIELDCI_API_KEY }}

Copilot uses AI. Check for mistakes.
SHIELDCI_TRIGGERED_BY: ${{ steps.meta.outputs.trigger }}
SHIELDCI_RESULTS_FILE: ${{ runner.temp }}/../../../Desktop/ShieldCI/tests/shield_results.json
run: |
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SHIELDCI_RESULTS_FILE is set to two different values: one via the job env: (with a brittle runner.temp + ../../../ traversal), then overridden in the step with export. This can lead to confusing behavior depending on which value push_results.py reads and makes the path resolution fragile. Use a single, consistent absolute path for SHIELDCI_RESULTS_FILE (preferably set once in env) and remove the conflicting override.

Suggested change
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

Copilot uses AI. Check for mistakes.
Comment on lines +2 to +3
"status": "Clean",
"vulnerabilities": [],

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This fixture is internally inconsistent: it marks the scan status as Clean and vulnerabilities as an empty list, while report_markdown describes multiple critical vulnerabilities. If downstream logic/tests rely on status/vulnerabilities to match the report, this will produce incorrect behavior. Align the JSON fields with the report content (e.g., non-clean status and populated vulnerabilities) or adjust the report_markdown to match a clean scan.

Suggested change
"status": "Clean",
"vulnerabilities": [],
"status": "Vulnerable",
"vulnerabilities": [
{
"id": "SQL_INJECTION_LOGIN",
"title": "SQL Injection in /login route",
"severity": "critical",
"description": "The GET /login route builds SQL queries via string concatenation using unsanitized user input, allowing SQL injection."
},
{
"id": "INSECURE_PASSWORD_STORAGE",
"title": "Insecure password storage",
"severity": "high",
"description": "Passwords are stored in plaintext instead of being hashed with a secure algorithm such as bcrypt."
},
{
"id": "IDOR_LOGIN",
"title": "Insecure Direct Object Reference in /login",
"severity": "high",
"description": "The /login route does not properly validate or sanitize the username parameter, potentially exposing sensitive user data."
}
],

Copilot uses AI. Check for mistakes.
@Akshat-Raj
Akshat-Raj merged commit 8b9f727 into Akshat-Raj:mainMar 7, 2026
2 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Zenith1415@Akshat-Raj
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Bugfixes by Zenith1415 · Pull Request #8 · Akshat-Raj/ShieldCI · GitHub
Skip to content

Bugfixes - #8

Merged
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes
Mar 7, 2026
Merged

Bugfixes#8
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes

Conversation

@Zenith1415

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI review requested due to automatic review settings March 7, 2026 02:09

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the ShieldCI security scanning workflow to support additional triggers and richer metadata, while adding generated scan artifacts under tests/ for reference.

Changes:

  • Expand GitHub Actions triggers (push + manual) and add event-aware metadata output.
  • Adjust workflow steps for config/repo copying, duration output, and PR-only commenting.
  • Add ShieldCI scan output artifacts (shield_results.json, scan_output.log) and a tests/repo subproject pointer.

Reviewed changes

Copilot reviewed 3 out of 5 changed files in this pull request and generated 3 comments.

FileDescription
tests/shield_results.jsonAdds a ShieldCI results JSON artifact including a markdown report payload
tests/scan_output.logAdds a captured ShieldCI orchestrator run log
tests/repoAdds a subproject commit pointer under tests
.github/workflows/shieldci.ymlExtends workflow triggers, metadata gathering, result pushing, and PR commenting logic

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +64 to +65
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The workflow hardcodes an API key (and an API URL) directly in the repository. This exposes credentials to anyone with repo access and to any workflow log/runner that can read the YAML. Move these values back to GitHub Secrets (e.g., secrets.SHIELDCI_API_URL / secrets.SHIELDCI_API_KEY) and avoid committing real keys to source control.

Suggested change
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec
SHIELDCI_API_URL: ${{ secrets.SHIELDCI_API_URL }}
SHIELDCI_API_KEY: ${{ secrets.SHIELDCI_API_KEY }}

Copilot uses AI. Check for mistakes.
SHIELDCI_TRIGGERED_BY: ${{ steps.meta.outputs.trigger }}
SHIELDCI_RESULTS_FILE: ${{ runner.temp }}/../../../Desktop/ShieldCI/tests/shield_results.json
run: |
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SHIELDCI_RESULTS_FILE is set to two different values: one via the job env: (with a brittle runner.temp + ../../../ traversal), then overridden in the step with export. This can lead to confusing behavior depending on which value push_results.py reads and makes the path resolution fragile. Use a single, consistent absolute path for SHIELDCI_RESULTS_FILE (preferably set once in env) and remove the conflicting override.

Suggested change
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

Copilot uses AI. Check for mistakes.
Comment on lines +2 to +3
"status": "Clean",
"vulnerabilities": [],

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This fixture is internally inconsistent: it marks the scan status as Clean and vulnerabilities as an empty list, while report_markdown describes multiple critical vulnerabilities. If downstream logic/tests rely on status/vulnerabilities to match the report, this will produce incorrect behavior. Align the JSON fields with the report content (e.g., non-clean status and populated vulnerabilities) or adjust the report_markdown to match a clean scan.

Suggested change
"status": "Clean",
"vulnerabilities": [],
"status": "Vulnerable",
"vulnerabilities": [
{
"id": "SQL_INJECTION_LOGIN",
"title": "SQL Injection in /login route",
"severity": "critical",
"description": "The GET /login route builds SQL queries via string concatenation using unsanitized user input, allowing SQL injection."
},
{
"id": "INSECURE_PASSWORD_STORAGE",
"title": "Insecure password storage",
"severity": "high",
"description": "Passwords are stored in plaintext instead of being hashed with a secure algorithm such as bcrypt."
},
{
"id": "IDOR_LOGIN",
"title": "Insecure Direct Object Reference in /login",
"severity": "high",
"description": "The /login route does not properly validate or sanitize the username parameter, potentially exposing sensitive user data."
}
],

Copilot uses AI. Check for mistakes.
@Akshat-Raj
Akshat-Raj merged commit 8b9f727 into Akshat-Raj:mainMar 7, 2026
2 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Zenith1415@Akshat-Raj
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Bugfixes by Zenith1415 · Pull Request #8 · Akshat-Raj/ShieldCI · GitHub
Skip to content

Bugfixes - #8

Merged
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes
Mar 7, 2026
Merged

Bugfixes#8
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes

Conversation

@Zenith1415

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI review requested due to automatic review settings March 7, 2026 02:09

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the ShieldCI security scanning workflow to support additional triggers and richer metadata, while adding generated scan artifacts under tests/ for reference.

Changes:

  • Expand GitHub Actions triggers (push + manual) and add event-aware metadata output.
  • Adjust workflow steps for config/repo copying, duration output, and PR-only commenting.
  • Add ShieldCI scan output artifacts (shield_results.json, scan_output.log) and a tests/repo subproject pointer.

Reviewed changes

Copilot reviewed 3 out of 5 changed files in this pull request and generated 3 comments.

FileDescription
tests/shield_results.jsonAdds a ShieldCI results JSON artifact including a markdown report payload
tests/scan_output.logAdds a captured ShieldCI orchestrator run log
tests/repoAdds a subproject commit pointer under tests
.github/workflows/shieldci.ymlExtends workflow triggers, metadata gathering, result pushing, and PR commenting logic

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +64 to +65
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The workflow hardcodes an API key (and an API URL) directly in the repository. This exposes credentials to anyone with repo access and to any workflow log/runner that can read the YAML. Move these values back to GitHub Secrets (e.g., secrets.SHIELDCI_API_URL / secrets.SHIELDCI_API_KEY) and avoid committing real keys to source control.

Suggested change
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec
SHIELDCI_API_URL: ${{ secrets.SHIELDCI_API_URL }}
SHIELDCI_API_KEY: ${{ secrets.SHIELDCI_API_KEY }}

Copilot uses AI. Check for mistakes.
SHIELDCI_TRIGGERED_BY: ${{ steps.meta.outputs.trigger }}
SHIELDCI_RESULTS_FILE: ${{ runner.temp }}/../../../Desktop/ShieldCI/tests/shield_results.json
run: |
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SHIELDCI_RESULTS_FILE is set to two different values: one via the job env: (with a brittle runner.temp + ../../../ traversal), then overridden in the step with export. This can lead to confusing behavior depending on which value push_results.py reads and makes the path resolution fragile. Use a single, consistent absolute path for SHIELDCI_RESULTS_FILE (preferably set once in env) and remove the conflicting override.

Suggested change
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

Copilot uses AI. Check for mistakes.
Comment on lines +2 to +3
"status": "Clean",
"vulnerabilities": [],

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This fixture is internally inconsistent: it marks the scan status as Clean and vulnerabilities as an empty list, while report_markdown describes multiple critical vulnerabilities. If downstream logic/tests rely on status/vulnerabilities to match the report, this will produce incorrect behavior. Align the JSON fields with the report content (e.g., non-clean status and populated vulnerabilities) or adjust the report_markdown to match a clean scan.

Suggested change
"status": "Clean",
"vulnerabilities": [],
"status": "Vulnerable",
"vulnerabilities": [
{
"id": "SQL_INJECTION_LOGIN",
"title": "SQL Injection in /login route",
"severity": "critical",
"description": "The GET /login route builds SQL queries via string concatenation using unsanitized user input, allowing SQL injection."
},
{
"id": "INSECURE_PASSWORD_STORAGE",
"title": "Insecure password storage",
"severity": "high",
"description": "Passwords are stored in plaintext instead of being hashed with a secure algorithm such as bcrypt."
},
{
"id": "IDOR_LOGIN",
"title": "Insecure Direct Object Reference in /login",
"severity": "high",
"description": "The /login route does not properly validate or sanitize the username parameter, potentially exposing sensitive user data."
}
],

Copilot uses AI. Check for mistakes.
@Akshat-Raj
Akshat-Raj merged commit 8b9f727 into Akshat-Raj:mainMar 7, 2026
2 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Zenith1415@Akshat-Raj
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Bugfixes by Zenith1415 · Pull Request #8 · Akshat-Raj/ShieldCI · GitHub
Skip to content

Bugfixes - #8

Merged
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes
Mar 7, 2026
Merged

Bugfixes#8
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes

Conversation

@Zenith1415

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI review requested due to automatic review settings March 7, 2026 02:09

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the ShieldCI security scanning workflow to support additional triggers and richer metadata, while adding generated scan artifacts under tests/ for reference.

Changes:

  • Expand GitHub Actions triggers (push + manual) and add event-aware metadata output.
  • Adjust workflow steps for config/repo copying, duration output, and PR-only commenting.
  • Add ShieldCI scan output artifacts (shield_results.json, scan_output.log) and a tests/repo subproject pointer.

Reviewed changes

Copilot reviewed 3 out of 5 changed files in this pull request and generated 3 comments.

FileDescription
tests/shield_results.jsonAdds a ShieldCI results JSON artifact including a markdown report payload
tests/scan_output.logAdds a captured ShieldCI orchestrator run log
tests/repoAdds a subproject commit pointer under tests
.github/workflows/shieldci.ymlExtends workflow triggers, metadata gathering, result pushing, and PR commenting logic

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +64 to +65
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The workflow hardcodes an API key (and an API URL) directly in the repository. This exposes credentials to anyone with repo access and to any workflow log/runner that can read the YAML. Move these values back to GitHub Secrets (e.g., secrets.SHIELDCI_API_URL / secrets.SHIELDCI_API_KEY) and avoid committing real keys to source control.

Suggested change
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec
SHIELDCI_API_URL: ${{ secrets.SHIELDCI_API_URL }}
SHIELDCI_API_KEY: ${{ secrets.SHIELDCI_API_KEY }}

Copilot uses AI. Check for mistakes.
SHIELDCI_TRIGGERED_BY: ${{ steps.meta.outputs.trigger }}
SHIELDCI_RESULTS_FILE: ${{ runner.temp }}/../../../Desktop/ShieldCI/tests/shield_results.json
run: |
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SHIELDCI_RESULTS_FILE is set to two different values: one via the job env: (with a brittle runner.temp + ../../../ traversal), then overridden in the step with export. This can lead to confusing behavior depending on which value push_results.py reads and makes the path resolution fragile. Use a single, consistent absolute path for SHIELDCI_RESULTS_FILE (preferably set once in env) and remove the conflicting override.

Suggested change
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

Copilot uses AI. Check for mistakes.
Comment on lines +2 to +3
"status": "Clean",
"vulnerabilities": [],

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This fixture is internally inconsistent: it marks the scan status as Clean and vulnerabilities as an empty list, while report_markdown describes multiple critical vulnerabilities. If downstream logic/tests rely on status/vulnerabilities to match the report, this will produce incorrect behavior. Align the JSON fields with the report content (e.g., non-clean status and populated vulnerabilities) or adjust the report_markdown to match a clean scan.

Suggested change
"status": "Clean",
"vulnerabilities": [],
"status": "Vulnerable",
"vulnerabilities": [
{
"id": "SQL_INJECTION_LOGIN",
"title": "SQL Injection in /login route",
"severity": "critical",
"description": "The GET /login route builds SQL queries via string concatenation using unsanitized user input, allowing SQL injection."
},
{
"id": "INSECURE_PASSWORD_STORAGE",
"title": "Insecure password storage",
"severity": "high",
"description": "Passwords are stored in plaintext instead of being hashed with a secure algorithm such as bcrypt."
},
{
"id": "IDOR_LOGIN",
"title": "Insecure Direct Object Reference in /login",
"severity": "high",
"description": "The /login route does not properly validate or sanitize the username parameter, potentially exposing sensitive user data."
}
],

Copilot uses AI. Check for mistakes.
@Akshat-Raj
Akshat-Raj merged commit 8b9f727 into Akshat-Raj:mainMar 7, 2026
2 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Zenith1415@Akshat-Raj
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Bugfixes by Zenith1415 · Pull Request #8 · Akshat-Raj/ShieldCI · GitHub
Skip to content

Bugfixes - #8

Merged
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes
Mar 7, 2026
Merged

Bugfixes#8
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes

Conversation

@Zenith1415

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI review requested due to automatic review settings March 7, 2026 02:09

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the ShieldCI security scanning workflow to support additional triggers and richer metadata, while adding generated scan artifacts under tests/ for reference.

Changes:

  • Expand GitHub Actions triggers (push + manual) and add event-aware metadata output.
  • Adjust workflow steps for config/repo copying, duration output, and PR-only commenting.
  • Add ShieldCI scan output artifacts (shield_results.json, scan_output.log) and a tests/repo subproject pointer.

Reviewed changes

Copilot reviewed 3 out of 5 changed files in this pull request and generated 3 comments.

FileDescription
tests/shield_results.jsonAdds a ShieldCI results JSON artifact including a markdown report payload
tests/scan_output.logAdds a captured ShieldCI orchestrator run log
tests/repoAdds a subproject commit pointer under tests
.github/workflows/shieldci.ymlExtends workflow triggers, metadata gathering, result pushing, and PR commenting logic

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +64 to +65
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The workflow hardcodes an API key (and an API URL) directly in the repository. This exposes credentials to anyone with repo access and to any workflow log/runner that can read the YAML. Move these values back to GitHub Secrets (e.g., secrets.SHIELDCI_API_URL / secrets.SHIELDCI_API_KEY) and avoid committing real keys to source control.

Suggested change
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec
SHIELDCI_API_URL: ${{ secrets.SHIELDCI_API_URL }}
SHIELDCI_API_KEY: ${{ secrets.SHIELDCI_API_KEY }}

Copilot uses AI. Check for mistakes.
SHIELDCI_TRIGGERED_BY: ${{ steps.meta.outputs.trigger }}
SHIELDCI_RESULTS_FILE: ${{ runner.temp }}/../../../Desktop/ShieldCI/tests/shield_results.json
run: |
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SHIELDCI_RESULTS_FILE is set to two different values: one via the job env: (with a brittle runner.temp + ../../../ traversal), then overridden in the step with export. This can lead to confusing behavior depending on which value push_results.py reads and makes the path resolution fragile. Use a single, consistent absolute path for SHIELDCI_RESULTS_FILE (preferably set once in env) and remove the conflicting override.

Suggested change
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

Copilot uses AI. Check for mistakes.
Comment on lines +2 to +3
"status": "Clean",
"vulnerabilities": [],

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This fixture is internally inconsistent: it marks the scan status as Clean and vulnerabilities as an empty list, while report_markdown describes multiple critical vulnerabilities. If downstream logic/tests rely on status/vulnerabilities to match the report, this will produce incorrect behavior. Align the JSON fields with the report content (e.g., non-clean status and populated vulnerabilities) or adjust the report_markdown to match a clean scan.

Suggested change
"status": "Clean",
"vulnerabilities": [],
"status": "Vulnerable",
"vulnerabilities": [
{
"id": "SQL_INJECTION_LOGIN",
"title": "SQL Injection in /login route",
"severity": "critical",
"description": "The GET /login route builds SQL queries via string concatenation using unsanitized user input, allowing SQL injection."
},
{
"id": "INSECURE_PASSWORD_STORAGE",
"title": "Insecure password storage",
"severity": "high",
"description": "Passwords are stored in plaintext instead of being hashed with a secure algorithm such as bcrypt."
},
{
"id": "IDOR_LOGIN",
"title": "Insecure Direct Object Reference in /login",
"severity": "high",
"description": "The /login route does not properly validate or sanitize the username parameter, potentially exposing sensitive user data."
}
],

Copilot uses AI. Check for mistakes.
@Akshat-Raj
Akshat-Raj merged commit 8b9f727 into Akshat-Raj:mainMar 7, 2026
2 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Zenith1415@Akshat-Raj
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Bugfixes by Zenith1415 · Pull Request #8 · Akshat-Raj/ShieldCI · GitHub
Skip to content

Bugfixes - #8

Merged
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes
Mar 7, 2026
Merged

Bugfixes#8
Akshat-Raj merged 2 commits into
Akshat-Raj:mainfrom
Zenith1415:bugfixes

Conversation

@Zenith1415

Copy link
Copy Markdown
Contributor

No description provided.

CopilotAI review requested due to automatic review settings March 7, 2026 02:09

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the ShieldCI security scanning workflow to support additional triggers and richer metadata, while adding generated scan artifacts under tests/ for reference.

Changes:

  • Expand GitHub Actions triggers (push + manual) and add event-aware metadata output.
  • Adjust workflow steps for config/repo copying, duration output, and PR-only commenting.
  • Add ShieldCI scan output artifacts (shield_results.json, scan_output.log) and a tests/repo subproject pointer.

Reviewed changes

Copilot reviewed 3 out of 5 changed files in this pull request and generated 3 comments.

FileDescription
tests/shield_results.jsonAdds a ShieldCI results JSON artifact including a markdown report payload
tests/scan_output.logAdds a captured ShieldCI orchestrator run log
tests/repoAdds a subproject commit pointer under tests
.github/workflows/shieldci.ymlExtends workflow triggers, metadata gathering, result pushing, and PR commenting logic

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +64 to +65
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The workflow hardcodes an API key (and an API URL) directly in the repository. This exposes credentials to anyone with repo access and to any workflow log/runner that can read the YAML. Move these values back to GitHub Secrets (e.g., secrets.SHIELDCI_API_URL / secrets.SHIELDCI_API_KEY) and avoid committing real keys to source control.

Suggested change
SHIELDCI_API_URL: http://localhost:3000
SHIELDCI_API_KEY: fc09420a3737855a3094ff7831a6219565cee6777a0fbeec
SHIELDCI_API_URL: ${{ secrets.SHIELDCI_API_URL }}
SHIELDCI_API_KEY: ${{ secrets.SHIELDCI_API_KEY }}

Copilot uses AI. Check for mistakes.
SHIELDCI_TRIGGERED_BY: ${{ steps.meta.outputs.trigger }}
SHIELDCI_RESULTS_FILE: ${{ runner.temp }}/../../../Desktop/ShieldCI/tests/shield_results.json
run: |
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SHIELDCI_RESULTS_FILE is set to two different values: one via the job env: (with a brittle runner.temp + ../../../ traversal), then overridden in the step with export. This can lead to confusing behavior depending on which value push_results.py reads and makes the path resolution fragile. Use a single, consistent absolute path for SHIELDCI_RESULTS_FILE (preferably set once in env) and remove the conflicting override.

Suggested change
export SHIELDCI_RESULTS_FILE="$HOME/Desktop/ShieldCI/tests/shield_results.json"

Copilot uses AI. Check for mistakes.
Comment on lines +2 to +3
"status": "Clean",
"vulnerabilities": [],

CopilotAIMar 7, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This fixture is internally inconsistent: it marks the scan status as Clean and vulnerabilities as an empty list, while report_markdown describes multiple critical vulnerabilities. If downstream logic/tests rely on status/vulnerabilities to match the report, this will produce incorrect behavior. Align the JSON fields with the report content (e.g., non-clean status and populated vulnerabilities) or adjust the report_markdown to match a clean scan.

Suggested change
"status": "Clean",
"vulnerabilities": [],
"status": "Vulnerable",
"vulnerabilities": [
{
"id": "SQL_INJECTION_LOGIN",
"title": "SQL Injection in /login route",
"severity": "critical",
"description": "The GET /login route builds SQL queries via string concatenation using unsanitized user input, allowing SQL injection."
},
{
"id": "INSECURE_PASSWORD_STORAGE",
"title": "Insecure password storage",
"severity": "high",
"description": "Passwords are stored in plaintext instead of being hashed with a secure algorithm such as bcrypt."
},
{
"id": "IDOR_LOGIN",
"title": "Insecure Direct Object Reference in /login",
"severity": "high",
"description": "The /login route does not properly validate or sanitize the username parameter, potentially exposing sensitive user data."
}
],

Copilot uses AI. Check for mistakes.
@Akshat-Raj
Akshat-Raj merged commit 8b9f727 into Akshat-Raj:mainMar 7, 2026
2 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Zenith1415@Akshat-Raj