False positive: js/incomplete-hostname-regexp treats LinkifyIt.match(text) as a regex call
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 55/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- javascript
- Área
- security
Línea de trabajo
Inspecciona la consulta js/incomplete-hostname-regexp y sus modelos de biblioteca, y luego compara el precedente de Sinon en PR 19854. Vuelve a ejecutar la alerta de CodeQL enlazada contra test/link-recognition-qualification.test.js; se habrá terminado cuando los literales de LinkifyIt.match(text) ya no se notifiquen, mientras los hallazgos de expresiones regulares de String.match ordinarios sigan habilitados.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Description of the false positive
js/incomplete-hostname-regexp treats the argument to LinkifyIt.match(text) as a regular expression. The receiver is a LinkifyIt instance from linkify-it@6.1.0; its argument is document text to scan for links, not a regex pattern. Literal dots in these URLs are therefore correct.
Observed with CodeQL 2.26.4, JavaScript/TypeScript analysis, build-mode: none, and github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938 (v4.37.9), using the default query suite without custom queries or exclusions.
Diagnostic on the text literal:
This string, which is used as a regular expression here, has an unescaped '.' before 'youtube.com/watc', so it might match more hosts than expected.
The linked use is scanner.match(text).
Code samples or links to source code
Small excerpt retaining the constructor, configuration, literal and call from the reported test:
import { LinkifyIt } from "linkify-it";
const scanner = new LinkifyIt({ fuzzyLink: false, fuzzyEmail: false })
.add("ftp:", null)
.add("mailto:", null)
.add("//", null);
const text =
"😀 *literal* (https://www.youtube.com/watch?v=tax4e4hBBZc), then https://store.steampowered.com/app/457140/.";
const matches = scanner.match(text);
console.log(matches.map((m) => m.raw));
With linkify-it@6.1.0, the API returns matches for the two literal URLs. The package's build/index.d.ts declares match(text: string): Match[] | null; build/index.mjs implements the method by scanning that document text with the library's link recognizers.
Exact reported source at the PR merge revision.
Source at the immutable PR head.
Validation: node --test test/link-recognition-qualification.test.js passes 1/1, including exact URL and offset assertions. The hosted CodeQL analysis reports the finding in the linked full test. The reduced excerpt above has not been separately analyzed with CodeQL; no claim is made that it is the smallest scanner reproducer.
Expected: recognize that this imported library's match method consumes document text, so these literals should not be classified as hostname regular expressions. Ordinary String.match regex findings should remain enabled.
Related precedent: https://github.com/github/codeql/pull/19854 explicitly models Sinon's match calls as non-RegExp. I found no existing linkify-it report in the upstream search.
URL to the alert on GitHub code scanning (optional)
https://github.com/MaksymShostak/steam-community-bbcode/security/code-scanning/2
- Lenguaje dominante
- CodeQL
- Estrellas
- 10.1k
- Forks
- 2.1k
- Merge medio
- 2 d 11 h
- PR fusionados (30 d)
- 129
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de github/codeql
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
-
C#: cs/simplifiable-boolean-expression false positive on Nullable<bool> compared with a literal Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
-
false-positive
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
-
False positive Abiertofalse-positive
Dificultad 4/5 3-5 días Aptitud para principiantes 15/100
Todos los issues de github/codeql
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
phoenixframework/phoenix#6847 ·
-
intake mcp-intake needs-ac needs-human-review priority:medium type:bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Ikalus1988/MisakaNet#2019 · 2 comentarios ·
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
avniproject/avni-client#2135 ·
-
agent/security hive/hosted-available-lke648397-260827-5n31 security
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
api7/lua-resty-saml#63 ·