mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-04 14:25:08 +00:00
Checked each one rather than blanket-suppressing. Python (Opengrep, 4). The Jinja2 environment disables autoescaping on purpose -- these templates emit Python, not HTML, and escaping a quote in a plugin name would corrupt the generated source. The safety comes from the values instead (_safe_int, _rgb_expr, _reject_source_breaking), which test_composer_code_injection.py covers. Both the Environment( line and the autoescape= line are reported separately, so each needs its own nosemgrep. The two "Flask route directly returning a formatted string" hits are not routes at all: _as_rgb_filter is a Jinja filter and _rgb_tuple a private helper, both emitting a Python tuple literal with every channel coerced to int first. JavaScript (Biome + ESLint, 14). useQwikValidLexicalScope fired five times on plain arrow-function consts -- it is a Qwik rule about the $() serialization boundary, and this is Alpine.js. noUnusedVariables flagged composerApp(), which the template calls as x-data="composerApp()", where the linter cannot see it. The eight detect-object-injection hits are array indices (this.elements[idx], rawVals[i]) or lookups on module-private maps keyed by an internal element type; none takes an attacker-supplied property name, so disabled per file with the reason rather than eight times inline. .codacy.yml only supports exclude_paths, so these have to be inline. Matches the repo's existing "eslint-disable-line <rule> -- <reason>" form. 372 composer tests pass, including the 14 JS contract tests that parse these two files. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014RRtqXDCnvnY6EQwhT5CV9