mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-16 23:52:40 -06:00
b9c6789560
* feat(secrets): add authenticated egress substitution proxy * feat(secrets): bind egress substitution to hosts * ci(codeql): classify egress proxy bypass tunnel in network boundary query * refactor(proxy-capture): use the canonical IP parser instead of node:net * fix(secrets): compare proxy tokens with a process-keyed MAC
39 lines
993 B
YAML
39 lines
993 B
YAML
name: openclaw-codeql-network-runtime-boundary-critical-quality
|
|
|
|
disable-default-queries: true
|
|
|
|
queries:
|
|
- uses: ./.github/codeql/openclaw-boundary/queries/raw-socket-callsite-classification.ql
|
|
- uses: ./.github/codeql/openclaw-boundary/queries/managed-proxy-runtime-mutation.ql
|
|
|
|
paths:
|
|
- src/cli/gateway-cli/run-loop.ts
|
|
- src/infra/gateway-lock.ts
|
|
- src/infra/jsonl-socket.ts
|
|
- src/infra/net
|
|
- src/infra/push-apns-http2.ts
|
|
- src/infra/ssh-tunnel.ts
|
|
- src/proxy-capture
|
|
- src/secrets/egress-proxy
|
|
- extensions/codex/src/app-server/transport-websocket.ts
|
|
- extensions/irc/src
|
|
- extensions/qa-lab/src
|
|
- packages/net-policy/src
|
|
|
|
paths-ignore:
|
|
- "**/node_modules"
|
|
- "**/coverage"
|
|
- "**/*.generated.ts"
|
|
- "**/*.bundle.js"
|
|
- "**/*-runtime.js"
|
|
- "**/*.test.ts"
|
|
- "**/*.test.tsx"
|
|
- "**/*.e2e.test.ts"
|
|
- "**/*.e2e.test.tsx"
|
|
- "**/*test-support*"
|
|
- "**/*test-helper*"
|
|
- "**/*mock*"
|
|
- "**/*fixture*"
|
|
- "**/*bench*"
|
|
- "extensions/diffs/assets/**"
|