google / google/licensecheck

<!-- ccr-overview-v2 -->

Open
#85 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
513
Forks
99
PR merge metrics
No merged PRs in 30d

Description

## Copilot review overview

### 🟡 Changes recommended

The sanitizer still has source-corruption and URL-masking edge cases that weaken its fidelity and security guarantees.

*Once you've addressed the issues Copilot identified, you can request another Copilot review.*

**Review tier:** Balanced
**Findings:** 4 Medium severity

New issues introduced by this change (4)

| Severity | Finding |
|:--:|:--|
| Medium severity | `pkg/​sanitize/​sanitize.go` — This fallback escapes every ampersand, including those inside inline, fenced, and indented code.… |
| Medium severity | `pkg/​sanitize/​sanitize.go` — The bare-URL detector treats every alphabetic `scheme://` token as safely visible, although the… |
| Medium severity | `pkg/​sanitize/​sanitize.go` — These loops cast individual UTF-8 bytes to runes, so Unicode whitespace is never recognized. With… |
| Medium severity | `pkg/​sanitize/​sanitize.go` — This lookup is case-sensitive even though URI schemes are case-insensitive. A valid CommonMark… |

What changed in this PR

Introduces Markdown-aware sanitization to preserve code-bearing GitHub content while neutralizing hidden constructs.

**Changes:**
- Adds Goldmark-based `sanitize.Content`.
- Applies it across bodies, comments, releases, commits, and sub-issues.
- Adds extensive tests, benchmarks, and license metadata.

| File | Description |
| ---- | ----------- |
| `pkg/​sanitize/​sanitize.go` | Implements Markdown-aware sanitization. |
| `pkg/​sanitize/​sanitize_test.go` | Tests fidelity, safety, and performance. |
| `pkg/​github/​minimal_types.go` | Applies content sanitization to converters. |
| `pkg/​github/​issues.go` | Sanitizes issue and sub-issue responses. |
| `pkg/​github/​issues_test.go` | Tests sub-issue sanitization. |
| `pkg/​github/​repositories.go` | Sanitizes releases and blame messages. |
| `pkg/​github/​repositories_test.go` | Tests release and blame behavior. |
| `pkg/​github/​discussions.go` | Preserves discussion body content. |
| `pkg/​github/​discussions_test.go` | Updates discussion expectations. |
| `pkg/​github/​projects.go` | Uses content policy for status updates. |
| `pkg/​github/​sanitize_coverage_test.go` | Expands policy coverage tests. |
| `go.mod` | Adds Goldmark dependency. |
| `go.sum` | Records Goldmark checksums. |
| `third-party/​github.com/​yuin/​goldmark/​LICENSE` | Adds Goldmark’s license. |
| `third-party-licenses.linux.md` | Updates Linux licenses. |
| `third-party-licenses.darwin.md` | Updates macOS licenses. |
| `third-party-licenses.windows.md` | Updates Windows licenses. |

---

💡 Add a `code-review` agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

_Originally posted by @copilot-pull-request-reviewer in https://github.com/github/github-mcp-server/pull/3177#pullrequestreview-5076335684_

Contributor guide

Open the contributing guide

Research direction

This is a Copilot review artifact referencing an unrelated pull request, not a focused change request for google/licensecheck. If the findings are relevant, start by verifying pkg/sanitize/sanitize.go and pkg/sanitize/sanitize_test.go, then determine whether the four reported edge cases belong in this repository.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.