Skip to content

[C++][Markdown][Security] Exclude Badges in Generated README.md#23163

Open
Chrimle wants to merge 2 commits intoOpenAPITools:masterfrom
Chrimle:cpp-remove-markdown-badges
Open

[C++][Markdown][Security] Exclude Badges in Generated README.md#23163
Chrimle wants to merge 2 commits intoOpenAPITools:masterfrom
Chrimle:cpp-remove-markdown-badges

Conversation

@Chrimle
Copy link
Contributor

@Chrimle Chrimle commented Mar 7, 2026

Embedding "Badges" in Markdown could pose varying Security risks. Although the currently generated Badges appear innocent, they will invoke HTTP GET requests to the embedded URLs. One of the badges, links to the MIT license, which is little-to-no-use, as a regular link would suffice. The other badge, links to a 404 page. Hence, keeping these badges around is just a security liability.

PR checklist

  • Read the contribution guidelines.
  • Pull Request title clearly describes the work in the pull request and Pull Request description provides details about how to validate the work. Missing information here may result in delayed response from the community.
  • Run the following to build the project and update samples:
    ./mvnw clean package || exit
    ./bin/generate-samples.sh ./bin/configs/*.yaml || exit
    ./bin/utils/export_docs_generators.sh || exit
    
    (For Windows users, please run the script in WSL)
    Commit all changed files.
    This is important, as CI jobs will verify all generator outputs of your HEAD commit as it would merge with master.
    These must match the expectations made by your contribution.
    You may regenerate an individual generator by passing the relevant config(s) as an argument to the script, for example ./bin/generate-samples.sh bin/configs/java*.
    IMPORTANT: Do NOT purge/delete any folders/files (e.g. tests) when regenerating the samples as manually written tests may be removed.
  • File the PR against the correct branch: master (upcoming 7.x.0 minor release - breaking changes with fallbacks), 8.0.x (breaking changes without fallbacks)
  • If your PR solves a reported issue, reference it using GitHub's linking syntax (e.g., having "fixes #123" present in the PR description)
  • If your PR is targeting a particular programming language, @mention the technical committee members, so they are more likely to review the pull request.

Summary by cubic

Remove Travis CI and MIT license badges from the cpp-qt-qhttpengine-server README template and update generated samples to match. This prevents external HTTP requests from badges and removes a broken link in generated README files.

Written for commit bc23a1c. Summary will update on new commits.

Chrimle added 2 commits March 7, 2026 12:55
Signed-off-by: Chrimle <28791817+Chrimle@users.noreply.github.com>
Signed-off-by: Chrimle <28791817+Chrimle@users.noreply.github.com>
@Chrimle Chrimle marked this pull request as ready for review March 7, 2026 12:04
@Chrimle
Copy link
Contributor Author

Chrimle commented Mar 7, 2026

Ready for review 🙌 @wing328

@Chrimle Chrimle changed the title [C++][MD][Security] Stop Including Badges in Generated README.md [C++][MD][Security] Exclude Badges in Generated README.md Mar 7, 2026
@Chrimle Chrimle changed the title [C++][MD][Security] Exclude Badges in Generated README.md [C++][Markdown][Security] Exclude Badges in Generated README.md Mar 7, 2026
Copy link
Contributor

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

@wing328
Copy link
Member

wing328 commented Mar 9, 2026

cc @bbdouglas (2017/07) @sreeshas (2017/08) @jfiala (2017/08) @lukoyanov (2017/09) @cbornet (2017/09) @jeff9finger (2018/01) @karismann (2019/03) @Zomzog (2019/04) @lwlee2608 (2019/10) @martin-mfg (2023/08)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants