Fix CodeQL comment tag filter finding

Patch is-unsafe's XML comment-close detector during builds so generated bundles recognize both HTML comment end forms and satisfy CodeQL until the dependency publishes a fix.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 277302b1-aa95-4012-817b-9752cdaee14e
This commit is contained in:
Bruno Borges
2026-07-29 16:18:54 -04:00
parent 6937f5eb31
commit ff11496cf1
4 changed files with 23 additions and 3 deletions
+1 -1
View File
@@ -60140,7 +60140,7 @@ const XML_PATTERNS = [
{
id: 'xml-comment-close',
description: '--> closes an enclosing XML comment',
pattern: /-->/,
pattern: /--!?>/,
},
{
id: 'xml-pi-close',
+1 -1
View File
@@ -91195,7 +91195,7 @@ const XML_PATTERNS = [
{
id: 'xml-comment-close',
description: '--> closes an enclosing XML comment',
pattern: /-->/,
pattern: /--!?>/,
},
{
id: 'xml-pi-close',
+1 -1
View File
@@ -9,7 +9,7 @@
"node": ">=24.0.0"
},
"scripts": {
"build": "ncc build -o dist/setup src/setup-java.ts && ncc build -o dist/cleanup src/cleanup-java.ts",
"build": "node scripts/patch-is-unsafe.mjs && ncc build -o dist/setup src/setup-java.ts && ncc build -o dist/cleanup src/cleanup-java.ts",
"format": "prettier --no-error-on-unmatched-pattern --write \"**/*.{ts,yml,yaml}\"",
"format-check": "prettier --no-error-on-unmatched-pattern --check \"**/*.{ts,yml,yaml}\"",
"lint": "eslint \"**/*.ts\"",
+20
View File
@@ -0,0 +1,20 @@
import {readFile, writeFile} from 'node:fs/promises';
const sourcePath = new URL('../node_modules/is-unsafe/src/contexts/xml.js', import.meta.url);
const vulnerablePattern = 'pattern: /-->/,';
const safePattern = 'pattern: /--!?>/,';
const source = await readFile(sourcePath, 'utf8');
// CodeQL treats this XML detector as an incomplete HTML comment-end filter.
if (source.includes(safePattern)) {
process.exit(0);
}
const occurrences = source.split(vulnerablePattern).length - 1;
if (occurrences !== 1) {
throw new Error(
`Expected one ${JSON.stringify(vulnerablePattern)} in ${sourcePath.pathname}, found ${occurrences}`
);
}
await writeFile(sourcePath, source.replace(vulnerablePattern, safePattern));