Add a generic check against "dangerous" Unicode codepoints
- Dominant language
- Java
- Stars
- 5.6k
- Forks
- 559
- Avg merge
- 1d 14h
- Merged PRs (30d)
- 43
Description
It would be nice if spotless could check for (and remove or error out) "dangerous" unicode codepoints.
See today's Rust security advisory: https://blog.rust-lang.org/2021/11/01/cve-2021-42574.html - According to this, the initial list of forbidden codepoints should contain: U+202A, U+202B, U+202C, U+202D, U+202E, U+2066, U+2067, U+2068, U+2069
Additionally, it would be nice to have a similar check against homoglyph attacks, but that is probably a bit more tricky to solve...
Contributor guide
Research direction
Start with issue #976 and the linked Rust security advisory to confirm the nine listed codepoints and the intended remove-or-error behavior. Review Spotless's existing check entry points to determine where a generic Unicode check belongs; done means detecting every listed codepoint and applying the chosen behavior.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security, tooling
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100