Remediate insecure auth/XML patterns and bump H2 to patched version - #129
Draft
patrick-vuong with Copilot wants to merge 2 commits into
Draft
Remediate insecure auth/XML patterns and bump H2 to patched version#129patrick-vuong with Copilot wants to merge 2 commits into
patrick-vuong with Copilot wants to merge 2 commits into
Conversation
Co-authored-by: patrick-vuong <107423518+patrick-vuong@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Remediate common static code issues and vulnerable dependencies
Remediate insecure auth/XML patterns and bump H2 to patched version
Jul 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR addresses the security remediation issue by removing common static-analysis findings in application code and updating a vulnerable direct dependency. Scope is intentionally narrow: auth/token generation, XML parsing hardening, and a single dependency version bump.
Auth service hardening (
WizardAuthService)Random→SecureRandomMD5→SHA-256hexhash,wizardId-tokensession token shape).XML import hardening (
WizardImportResource)DocumentBuilderFactoryto prevent XXE/entity expansion attacks:Vulnerable dependency remediation
com.h2database:h2from2.2.224to2.3.232.Focused regression coverage
This change was produced with Moderne CLI and Moderne Agent Tools (MCP), informed by Moderne Prethink context (dependencies, test gaps, project identity).