Update main-os to latest upstream with OS customizations#50
Update main-os to latest upstream with OS customizations#50
Conversation
Bumps [minimatch](https://github.com/isaacs/minimatch) from 9.0.5 to 9.0.9. - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v9.0.5...v9.0.9) --- updated-dependencies: - dependency-name: minimatch dependency-version: 9.0.9 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps and [minimatch](https://github.com/isaacs/minimatch). These dependencies needed to be updated together. Updates `minimatch` from 10.1.1 to 10.2.4 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v10.1.1...v10.2.4) Updates `minimatch` from 3.1.2 to 3.1.5 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v10.1.1...v10.2.4) Updates `minimatch` from 9.0.5 to 9.0.9 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v10.1.1...v10.2.4) --- updated-dependencies: - dependency-name: minimatch dependency-version: 10.2.4 dependency-type: indirect - dependency-name: minimatch dependency-version: 3.1.5 dependency-type: indirect - dependency-name: minimatch dependency-version: 9.0.9 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [minimatch](https://github.com/isaacs/minimatch) to 3.1.5 and updates ancestor dependencies and [minimatch](https://github.com/isaacs/minimatch). These dependencies need to be updated together. Updates `minimatch` from 3.1.2 to 3.1.5 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.1.2...v3.1.5) Updates `minimatch` from 9.0.5 to 9.0.9 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.1.2...v3.1.5) Updates `minimatch` from 5.1.6 to 5.1.9 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.1.2...v3.1.5) --- updated-dependencies: - dependency-name: minimatch dependency-version: 3.1.5 dependency-type: direct:development - dependency-name: minimatch dependency-version: 9.0.9 dependency-type: indirect - dependency-name: minimatch dependency-version: 5.1.9 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…osoft#298658) Bumps [minimatch](https://github.com/isaacs/minimatch) from 3.1.2 to 3.1.5. - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.1.2...v3.1.5) --- updated-dependencies: - dependency-name: minimatch dependency-version: 3.1.5 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
microsoft#298423) fix(json.schemaDownload.trustedDomains): avoid always update json.schemaDownload.trustedDomains Signed-off-by: loongtao.zhang <loongtao.zhang@outlook.com>
…icrosoft#298610) * feat: add support for Copilot user agents and related functionality * Update comments * Updates
… across notification elements
…tency style(find-widget): unify border-radius with CSS variable for consistency style(inline-chat-gutter-menu): update border-radius to use CSS variable for consistency
…iable for consistency
…ncy with theme variable
…stency with theme variable
…s to more kinds (microsoft#299060) * modal - improve handling of Escape key and expand use of modal editors to more kinds * Update src/vs/workbench/browser/parts/editor/editorCommands.ts Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
…n CLI envs (microsoft#299117) * eng - explain fallback for how to check for compilation issues fast in CLI envs * Update .github/copilot-instructions.md Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * Update .github/copilot-instructions.md Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * . --------- Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Git - tweak copilot worktree folder detection * Pull request feedback
- Add customIcon field to CompletionItem interface (languages.ts, was modes.ts) - Add custom icon rendering logic in suggestWidgetRenderer.ts (moved to browser/ subfolder) - Add OS Azure Pipelines build/deploy pipeline for monaco-editor-core
Wiz Scan Summary
|
| Scanner | Findings |
|---|---|
| 1 |
|
| 2 |
|
| - | |
| 1 |
|
| 149 |
|
| - | |
| Total | 2 |
To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.
Pull Request Developer Guidance
Questions? See the Wiz FAQ.
Please contact the Security Office if you encounter issues with Wiz PR scanning.
There was a problem hiding this comment.
More Details
Vulnerabilities [russh:0.37.1]
| Name | Severity | Source | Fixed version | CVSS score | CVSS exploitability score | Has public exploit | Has CISA KEV exploit |
|---|---|---|---|---|---|---|---|
| CVE-2023-48795 | GHSA-45x7-px36-x8w8 | 0.40.2 | 5.9 | 2.2 | true | false | |
| CVE-2024-43410 | GHSA-vgvv-x7xg-6cqg | 0.44.1 | 7.5 | 3.9 | true | false | |
| CVE-2025-54804 | GHSA-h5rc-j5f5-3gcm | 0.54.1 | 6.5 | 2.8 | true | false |
To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason
If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).
To get more details on how to remediate this issue using AI, reply to this conversation with #wiz remediate
| @@ -1,5 +1,5 @@ | |||
| FROM ubuntu | |||
| MAINTAINER Kimbro Staken | |||
| FROM mcr.microsoft.com/devcontainers/base:ubuntu | |||
There was a problem hiding this comment.
Missing User Instruction
on resource FROM mcr.microsoft.com/devcontainers/base:ubuntu AS mcr.microsoft.com/devcontainers/base:ubuntu
More Details
This rule checks whether a `USER` instruction is specified in the Dockerfile. The rule fails when the `USER` instruction is missing, causing the container to run with root privileges (UID 0). If an attacker compromises an application running as root, they gain the privileges needed to potentially escape the container and attack the host node. It also increases the blast radius of a breach, allowing full control to modify files or install malware within the container. Enforcing a non-root user is a fundamental security measure that minimizes the attack surface and contains the impact of a potential compromise.
Expected
The Dockerfile stage should contain the 'USER' instruction
Found
The Dockerfile stage does not contain any 'USER' instruction
Rule ID: 6cd7a272-d9d1-4667-8224-73140fbaabdd
To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason
If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).
To get more details on how to remediate this issue using AI, reply to this conversation with #wiz remediate
|
I did a high level check of the code in person with Tiago |
Summary
Brings
main-osup to date with ourmainbranch (synced with microsoft/vscode), while preserving all OutSystems-specific customizations.OS customizations ported
customIcononCompletionItem— addscustomIcon?: HTMLElementto the interface inlanguages.ts(the file formerly known asmodes.ts)suggestWidgetRenderer.ts(now underbrowser/subfolder) now checks forcustomIconbefore the standard kind-based icon logic, and renders the custom element insideiconContainerbuild/azure-pipelines/os-monaco-core-pipeline.ymlrestored for the monaco-editor-core build/deploy pipelineCommits from main-os that were NOT ported (already upstream or not needed)
92cc555Fix microsoft#178795 (Luis Oliveira)75e0085Update version5a1b499,93376c6,7db1a2b,9580998,7e87a0b,022e0ab,b5ae100mainTest plan
CompletionItem.customIconis accessible in monaco-editor consumerscustomIconis set on a completion itemmain-osbranch