Skip to content

refactor: improve env expand regex #3037

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jan 27, 2025

Conversation

EvgenyWas
Copy link
Contributor

@EvgenyWas EvgenyWas commented Jan 26, 2025

πŸ”— Linked issue

Reference: nuxt/nuxt#30263

❓ Type of change

  • πŸ“– Documentation (updates to the documentation, readme, or JSdoc annotations)
  • 🐞 Bug fix (a non-breaking change that fixes an issue)
  • πŸ‘Œ Enhancement (improving an existing functionality like performance)
  • ✨ New feature (a non-breaking change that adds functionality)
  • 🧹 Chore (updates to the build process or auxiliary tools and libraries)
  • ⚠️ Breaking change (fix or feature that would cause existing functionality to change)

πŸ“š Description

The current Regex for env expansion feature is vulnerable according to Devina ReDos checker.

This Enhancement makes the Regex safe with keeping functionality.

πŸ“ Checklist

  • I have linked an issue or discussion.
  • I have updated the documentation accordingly.

@EvgenyWas EvgenyWas marked this pull request as ready for review January 26, 2025 14:29
@EvgenyWas EvgenyWas requested a review from pi0 as a code owner January 26, 2025 14:29
@pi0 pi0 changed the title fix: improve env expand regex safeness according to Devina ReDos checker refactor: improve env expand regex Jan 27, 2025
Copy link
Member

@pi0 pi0 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks! (although CI seems failing)

@EvgenyWas
Copy link
Contributor Author

Thanks! (although CI seems failing)

It's fine now. Previously, I checked the logs, and it seems there were piping errors independent of my changes.

@pi0 pi0 merged commit e6431c3 into nitrojs:v2 Jan 27, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants