From cceb041cf1ea051b7e60df2744587a0e07de3f6c Mon Sep 17 00:00:00 2001 From: Anton Arnaudov Date: Wed, 30 Sep 2026 18:36:54 +0300 Subject: [PATCH] test: close CodeQL's three findings in the webview-ui test helpers The fake DOM strips tags until nothing changes, so a nested '<b>' cannot leave a tag behind; the escaping tests check for raw markup with includes() instead of a regex CodeQL reads as an HTML filter. Co-Authored-By: Claude Opus 5.5 (1M context) --- packages/webview-ui/test/avatar.cov.test.ts | 2 +- packages/webview-ui/test/fakeDom.cov.ts | 10 +++++++++- packages/webview-ui/test/refTip.cov.test.ts | 2 +- 3 files changed, 11 insertions(+), 3 deletions(-) diff --git a/packages/webview-ui/test/avatar.cov.test.ts b/packages/webview-ui/test/avatar.cov.test.ts index 8d425498..a28966ae 100644 --- a/packages/webview-ui/test/avatar.cov.test.ts +++ b/packages/webview-ui/test/avatar.cov.test.ts @@ -93,7 +93,7 @@ test("a photo that already loaded once renders visible straight away", () => { test("the avatar markup escapes the name, the ring and the URL", () => { const html = avatarHtml("