fix(SEC-005): tighten cross-repo regex to eliminate false positive on frontmatter_hash_pure.cjs - #46568
Merged
pelikhan merged 3 commits intoJul 19, 2026
Conversation
…ntmatter_hash_pure.cjs Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Fix false-positive in SEC-005 conformance checker
fix(SEC-005): tighten cross-repo regex to eliminate false positive on frontmatter_hash_pure.cjs
Jul 19, 2026
pelikhan
approved these changes
Jul 19, 2026
pelikhan
marked this pull request as ready for review
July 19, 2026 07:35
pelikhan
deleted the
copilot/sec-005-fix-conformance-checker-false-positive
branch
July 19, 2026 07:35
Contributor
There was a problem hiding this comment.
Pull request overview
Narrows SEC-005 matching to avoid unrelated target/repo false positives.
Changes:
- Matches canonical target-repository identifiers with word boundaries.
- One issue remains: handlers using
resolveTargetRepoConfigare skipped.
Show a summary per file
| File | Description |
|---|---|
scripts/check-safe-outputs-conformance.sh |
Refines SEC-005 cross-repository detection. |
Review details
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Medium
Comment on lines
+180
to
+181
| # Check if handler supports target-repo (match explicit config-surface identifiers only) | ||
| if grep -qE "\btarget-repo\b|\btargetRepo\b|\btarget_repo\b" "$handler"; then |
Contributor
|
🎉 This pull request is included in a new release. Release: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
SEC-005 conformance checker falsely flagged
frontmatter_hash_pure.cjsbecause the loose patterntarget.*[Rr]epomatchedtargetandrepoas unrelated tokens on the same line — a symlink resolution call, not a cross-repo config surface.Changes
scripts/check-safe-outputs-conformance.sh: Replace the loosetarget.*[Rr]epo\|targetRepopattern with explicit config-surface identifiers anchored by word boundaries:The new pattern matches only the three canonical forms of the config parameter (kebab, camelCase, snake_case) and uses
\bto prevent substring hits inside longer identifiers. Genuine cross-repo handlers (e.g.apply_samples.cjs,close_pull_request.cjs) all use one of these explicit forms and continue to be detected.