CodeQL is now enabled on pushes, pull requests, and a weekly schedule. Its initial baseline identified 20 open alerts that need explicit review rather than silent dismissal.
Security dashboard: https://github.com/nguyenthdat/opencode-multi-auth-codex/security/code-scanning
High-severity groups
Medium-severity groups
Acceptance criteria
CodeQL is now enabled on pushes, pull requests, and a weekly schedule. Its initial baseline identified 20 open alerts that need explicit review rather than silent dismissal.
Security dashboard: https://github.com/nguyenthdat/opencode-multi-auth-codex/security/code-scanning
High-severity groups
js/disabling-certificate-validationatsrc/web.ts:3028js/file-system-raceatsrc/web.ts:3125js/remote-property-injectionatsrc/store.ts:535,src/store.ts:550, andsrc/store.ts:570js/user-controlled-bypassat five request-handling locations insrc/web.tsjs/insecure-temporary-filein three test filesjs/bad-tag-filterintests/web-headless/dashboard-smoke.test.tsMedium-severity groups
js/http-to-file-accessinsrc/logger.tsandsrc/store.tsjs/log-injectionatsrc/auth.ts:258js/stack-trace-exposureatsrc/web.ts:2332js/identity-replacementatsrc/index.ts:312Acceptance criteria
bun audit, and the full Bun test suite green.