Skip to content

Fix security issues - #1378

Open
bpander wants to merge 2 commits into
masterfrom
fix-code-scanning-issues
Open

bpander wants to merge 2 commits into
masterfrom
fix-code-scanning-issues

Conversation

@bpander

@bpander bpander commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Fix security issues flagged in https://github.com/metabase/metabase.github.io/pull/6651/checks?check_run_id=113024868999

They're also flagged in this repo: https://github.com/metabase/docs.metabase.github.io/security/code-scanning

Fixing them now so they don't get flagged in the docs->monorepo migration and because they're easy and we should do them anyway.

@bpander bpander self-assigned this Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Commit 231822c is live at https://docs-pr-1378-metaboat.vercel.app

Project Deployment Actions Updated (UTC)
docs 🟢 Ready Preview Oct 9, 2026 1:27pm

Deployed to Vercel via GitHub Actions

@bpander
bpander force-pushed the fix-code-scanning-issues branch from 9a3f820 to c016525 Compare October 8, 2026 17:52
@bpander
bpander force-pushed the fix-code-scanning-issues branch from c016525 to 658af28 Compare October 8, 2026 18:21
@bpander
bpander marked this pull request as ready for review October 8, 2026 18:30
@bpander
bpander requested a review from a team October 8, 2026 18:31
Comment thread public/docs/js/anonymous-snowplow.js Outdated
referrerUrl = document.referrer ? new URL(document.referrer) : null;
} catch (e) {
// Ignore invalid referrer URLs
referrerUrl = null;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unnecessary since it repeats the default value...

Comment thread public/docs/js/marketing-snowplow.js Outdated
referrerUrl = document.referrer ? new URL(document.referrer) : null;
} catch (e) {
// Ignore invalid referrer URLs
referrerUrl = null;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unnecessary since it repeats the default value...

Comment thread public/docs/js/anonymous-snowplow.js Outdated
}

// custom referrer (only for metabase.com)
var referrerUrl = null;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since everything is named with the Anon suffix, should we have the same for that? Meaning referrerUrlAnon... it might create a "collision" with the other referrerUrl ;)

@bpander
bpander force-pushed the fix-code-scanning-issues branch from ef1b3f0 to 231822c Compare October 9, 2026 13:21
@bpander

bpander commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

@losrebellos Thanks for the feedback! Addressed the comments in 231822c.

@bpander
bpander requested a review from losrebellos October 9, 2026 13:23

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants