Skip to content

Fix CodeQL, Dependabot, and README badges#3

Merged
timothywarner merged 4 commits into
mainfrom
claude/fix-ci-and-badges-019rxXmr1ghwm953gHGybQE9
Dec 6, 2025
Merged

Fix CodeQL, Dependabot, and README badges#3
timothywarner merged 4 commits into
mainfrom
claude/fix-ci-and-badges-019rxXmr1ghwm953gHGybQE9

Conversation

@timothywarner
Copy link
Copy Markdown
Contributor

No description provided.

- CodeQL: Removed Java-Kotlin analysis, now JavaScript-only
- Dependabot: Simplified config, removed non-existent directories,
  reduced noise with weekly/monthly schedules and grouped updates
- README: Fixed badges with branch=main param, removed PR-only badge
Documents 5 plausible security issues found in the codebase:
- Session cookie misconfiguration in NodeGoat
- Disabled Helmet middleware
- IDOR vulnerability in demo app
- Terraform state encryption concerns
- XSS vulnerabilities in vulnerable React demo
Executable script with all 5 security issues including:
- Full issue bodies with code examples
- Labels: security, vulnerability, priority levels
- Assignee: timothywarner
- Detailed remediation guidance
650+ lines covering:
- All prompts from Lessons 1-5 (vulnerability detection, security
  protocols, automated testing, code review, compliance)
- 50+ bonus advanced prompts for API security, container security,
  cloud security, penetration testing, forensics, and training
- Quick reference card for common prompt patterns
- Tips for effective security prompting
@timothywarner timothywarner merged commit de7496b into main Dec 6, 2025
9 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants