From caf0b0d73e5ce999490853c8dffe8c7aa566a91b Mon Sep 17 00:00:00 2001 From: Jason White Date: Mon, 18 Mar 2024 22:26:38 +0000 Subject: [PATCH 1/3] java file change --- .../org/owasp/webgoat/lessons/clientsidefiltering/Salaries.java | 1 + 1 file changed, 1 insertion(+) diff --git a/src/main/java/org/owasp/webgoat/lessons/clientsidefiltering/Salaries.java b/src/main/java/org/owasp/webgoat/lessons/clientsidefiltering/Salaries.java index 984af10d17..0329f7be49 100644 --- a/src/main/java/org/owasp/webgoat/lessons/clientsidefiltering/Salaries.java +++ b/src/main/java/org/owasp/webgoat/lessons/clientsidefiltering/Salaries.java @@ -92,6 +92,7 @@ public List> invoke() { sb.append("/Employees/Employee/LastName | "); sb.append("/Employees/Employee/SSN | "); sb.append("/Employees/Employee/Salary "); + // foo bar String expression = sb.toString(); nodes = (NodeList) path.evaluate(expression, inputSource, XPathConstants.NODESET); From 95cebaac4f8ebc0395d18afb5476bafc8218e93d Mon Sep 17 00:00:00 2001 From: Jason White Date: Mon, 18 Mar 2024 22:29:12 +0000 Subject: [PATCH 2/3] java change --- .github/workflows/semgrep.yml | 3 +-- .../owasp/webgoat/lessons/clientsidefiltering/Salaries.java | 2 +- 2 files changed, 2 insertions(+), 3 deletions(-) diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml index 03eaaa5c18..d7cc015b50 100644 --- a/.github/workflows/semgrep.yml +++ b/.github/workflows/semgrep.yml @@ -34,11 +34,10 @@ jobs: - name: checkout to develop branch run: | - git remote -v git config --global --add safe.directory /__w/WebGoat/WebGoat + git remote -v git checkout develop git pull origin develop - - name: scan on diff files only run: | diff --git a/src/main/java/org/owasp/webgoat/lessons/clientsidefiltering/Salaries.java b/src/main/java/org/owasp/webgoat/lessons/clientsidefiltering/Salaries.java index 0329f7be49..d5deee8429 100644 --- a/src/main/java/org/owasp/webgoat/lessons/clientsidefiltering/Salaries.java +++ b/src/main/java/org/owasp/webgoat/lessons/clientsidefiltering/Salaries.java @@ -92,7 +92,7 @@ public List> invoke() { sb.append("/Employees/Employee/LastName | "); sb.append("/Employees/Employee/SSN | "); sb.append("/Employees/Employee/Salary "); - // foo bar + // foo bar baz String expression = sb.toString(); nodes = (NodeList) path.evaluate(expression, inputSource, XPathConstants.NODESET); From 95045381ceb6252f249ba98aba5632c66fdacf4d Mon Sep 17 00:00:00 2001 From: Jason White Date: Mon, 18 Mar 2024 22:32:22 +0000 Subject: [PATCH 3/3] yolo --- .github/workflows/semgrep.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml index 03bc46cfd1..0150621ce9 100644 --- a/.github/workflows/semgrep.yml +++ b/.github/workflows/semgrep.yml @@ -36,7 +36,7 @@ jobs: run: | git config --global --add safe.directory /__w/WebGoat/WebGoat git remote -v - git checkout develop + git checkout origin develop git pull origin develop - name: scan on diff files only