SONARHTML-262 Add Electron webview security rules#677
SONARHTML-262 Add Electron webview security rules#677erwan-leforestier-sonarsource wants to merge 2 commits into
Conversation
Agentic Analysis: Early ResultsAgentic Analysis and Context Augmentation are available on your project. Here are some issues that could have been prevented. Follow the links to learn how to put them into action. 1 issue(s) found across 1 file(s):
Analyzed by SonarQube Agentic Analysis in 3.6 s |
|
Functional Validation artifact: SONARHTML-262-fv.zip |
Ruling Report✅ No changes to ruling expected issues in this PR |
|
Code Review ✅ Approved 1 resolved / 1 findingsImplements new Electron webview security rules S7074 and S7071 to detect insecure attributes and sandboxing configurations. The unused CheckForNull import was removed, and no further issues were found. ✅ 1 resolved✅ Quality: Unused import
|
| Auto-apply | Compact |
|
|
Was this helpful? React with 👍 / 👎 | Gitar




Summary
Add the new Electron
<webview>security rules fordisablewebsecurityand sandboxing in HTML, bundling SONARHTML-262 with SONARHTML-263.Changes
S7074andS7071HTML checks for insecure Electron<webview>attributesS7071andS7074rule resources and activate both in Sonar wayFunctional Validation
Attached:
SONARHTML-262-fv.zipUnzip and run:
./run.sh
Expected output is in
expected-output.txt. The README shows thebefore/after comparison so you can reproduce the difference directly.