diffplug / diffplug/spotless

Add a generic check against "dangerous" Unicode codepoints

Open
#976 0 comments 3 reactions 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
5.6k
Forks
559
Avg merge
1d 14h
Merged PRs (30d)
43

Description

It would be nice if spotless could check for (and remove or error out) "dangerous" unicode codepoints.

See today's Rust security advisory: https://blog.rust-lang.org/2021/11/01/cve-2021-42574.html - According to this, the initial list of forbidden codepoints should contain: U+202A, U+202B, U+202C, U+202D, U+202E, U+2066, U+2067, U+2068, U+2069

Additionally, it would be nice to have a similar check against homoglyph attacks, but that is probably a bit more tricky to solve...

Contributor guide

Open the contributing guide

Research direction

Start with issue #976 and the linked Rust security advisory to confirm the nine listed codepoints and the intended remove-or-error behavior. Review Spotless's existing check entry points to determine where a generic Unicode check belongs; done means detecting every listed codepoint and applying the chosen behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security, tooling
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.