newrelic / nr1-github

NR1 Github allows you to create more context to your entities by having access to the GitHub repository, contributors and README.
https://github.com/newrelic/nr1-github/discussions
Apache License 2.0
19 stars 27 forks source link

Fix XSS vulnerability for github links #73

Closed aswanson-nr closed 3 years ago

aswanson-nr commented 3 years ago

We had a report of a vulnerability in this nerdpack that we'll want to resolve. please refer to the internal JIRA issue for specifics

Suggested solutions include reseting the repository URL and the token when the Github URL is changed and displaying a message about the URLs being changed.

Acceptance Criteria