Join GitHub today
GitHub is home to over 20 million developers working together to host and review code, manage projects, and build software together.
web-ext lint results #31
Comments
added a commit
that referenced
this issue
Dec 12, 2017
biancadanforth
closed this
in
1c4337e
Dec 12, 2017
added a commit
that referenced
this issue
Dec 12, 2017
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
pdehaan commentedDec 11, 2017
... nothing too surprising here. Feel free to close if you don't feel scared by the output.
The "NOTICE" is the following naughty word (per mozilla/addons-linter /src/badwords.json): https://github.com/gregglind/addon-wr/blob/191d7b000265e174d38a5bcc77d76e67a792dd9e/addon/webextension/background.js#L18
The "WARNING" is the unsanitized
.innerHTMLset, at: https://github.com/gregglind/addon-wr/blob/191d7b000265e174d38a5bcc77d76e67a792dd9e/addon/webextension/content-script.js#L56-L61Not sure if there is a better way to construct links/DOM, but considering the anchor href is set from a
const, I don't think there is any XSS risks. But when in doubt, we could ask the sec team.