Replace Duktape 1.0.2 with QuickJS 2026-06-04 (ES2025) - #221
Replace Duktape 1.0.2 with QuickJS 2026-06-04 (ES2025)#221evgeny-boger wants to merge 18 commits into
146 new issues (0 max.) of at least severity.
Annotations
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2025-22870: golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net) (update to 1.24.1)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2025-22871: net/http: Request smuggling due to acceptance of invalid chunked data in net/http) (update to 1.24.2)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2025-4673: net/http: Sensitive headers not cleared on cross-origin redirect in net/http) (update to 1.24.4)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2025-47907: database/sql: Postgres Scan Race Condition) (update to 1.24.6)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2025-47912: net/url: Insufficient validation of bracketed IPv6 hostnames in net/url) (update to 1.24.8)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2025-58185: encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1) (update to 1.24.8)
Check notice on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2025-58186: golang.org/net/http: Lack of limit when parsing cookies can cause memory exhaustion in net/http) (update to 1.24.8)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2025-58188: crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509) (update to 1.24.8)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2025-58189: crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information) (update to 1.24.8)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2025-61724: net/textproto: Excessive CPU consumption in Reader.ReadResponse in net/textproto) (update to 1.24.8)
Check failure on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2025-68121: crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption) (update to 1.24.13)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2026-25679: net/url: Incorrect parsing of IPv6 host literals in net/url) (update to 1.25.8)
Check notice on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2026-27139: os: FileInfo can escape from a Root in golang os module) (update to 1.25.8)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2026-32288: archive/tar: golang: Go's archive/tar package: Denial of Service via maliciously-crafted archive) (update to 1.25.9)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2026-33811: net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME) (update to 1.25.10)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2026-39820: net/mail: golang: Go net/mail: Denial of Service via crafted email inputs) (update to 1.25.10)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2026-39823: html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content) (update to 1.25.10)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2026-39825: net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls) (update to 1.25.10)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2026-39836: ELSA-2026-22121: golang security update (IMPORTANT)) (update to 1.25.10)
Check warning on line 3 in internal/quickjsduk/go.mod
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/go.mod#L3
Insecure dependency golang/stdlib@v1.24.0 (CVE-2026-42507: net/textproto: golang: Golang net/textproto: Misleading error messages via input injection) (update to 1.25.11)
Check failure on line 118 in internal/quickjsduk/shim.c
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/shim.c#L118
Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126).
Check warning on line 118 in internal/quickjsduk/shim.c
codacy-production / Codacy Static Code Analysis
internal/quickjsduk/shim.c#L118
The `strlen` family of functions does not handle strings that are not null terminated.
Check warning on line 2 in sample-bench.js
codacy-production / Codacy Static Code Analysis
sample-bench.js#L2
'defineVirtualDevice' is not defined.
Check warning on line 11 in sample-bench.js
codacy-production / Codacy Static Code Analysis
sample-bench.js#L11
'defineRule' is not defined.
Check warning on line 13 in sample-bench.js
codacy-production / Codacy Static Code Analysis
sample-bench.js#L13
'dev' is not defined.