diff --git a/dist/cleanup/index.js b/dist/cleanup/index.js index 3d6bd159..25b91ffa 100644 --- a/dist/cleanup/index.js +++ b/dist/cleanup/index.js @@ -60140,7 +60140,7 @@ const XML_PATTERNS = [ { id: 'xml-comment-close', description: '--> closes an enclosing XML comment', - pattern: /-->/, + pattern: /--!?>/, }, { id: 'xml-pi-close', diff --git a/dist/setup/index.js b/dist/setup/index.js index a8f9406d..25673314 100644 --- a/dist/setup/index.js +++ b/dist/setup/index.js @@ -91195,7 +91195,7 @@ const XML_PATTERNS = [ { id: 'xml-comment-close', description: '--> closes an enclosing XML comment', - pattern: /-->/, + pattern: /--!?>/, }, { id: 'xml-pi-close', diff --git a/package.json b/package.json index abe6c7cd..9770c8d2 100644 --- a/package.json +++ b/package.json @@ -9,7 +9,7 @@ "node": ">=24.0.0" }, "scripts": { - "build": "ncc build -o dist/setup src/setup-java.ts && ncc build -o dist/cleanup src/cleanup-java.ts", + "build": "node scripts/patch-is-unsafe.mjs && ncc build -o dist/setup src/setup-java.ts && ncc build -o dist/cleanup src/cleanup-java.ts", "format": "prettier --no-error-on-unmatched-pattern --write \"**/*.{ts,yml,yaml}\"", "format-check": "prettier --no-error-on-unmatched-pattern --check \"**/*.{ts,yml,yaml}\"", "lint": "eslint \"**/*.ts\"", diff --git a/scripts/patch-is-unsafe.mjs b/scripts/patch-is-unsafe.mjs new file mode 100644 index 00000000..5a9f09ea --- /dev/null +++ b/scripts/patch-is-unsafe.mjs @@ -0,0 +1,20 @@ +import {readFile, writeFile} from 'node:fs/promises'; + +const sourcePath = new URL('../node_modules/is-unsafe/src/contexts/xml.js', import.meta.url); +const vulnerablePattern = 'pattern: /-->/,'; +const safePattern = 'pattern: /--!?>/,'; +const source = await readFile(sourcePath, 'utf8'); + +// CodeQL treats this XML detector as an incomplete HTML comment-end filter. +if (source.includes(safePattern)) { + process.exit(0); +} + +const occurrences = source.split(vulnerablePattern).length - 1; +if (occurrences !== 1) { + throw new Error( + `Expected one ${JSON.stringify(vulnerablePattern)} in ${sourcePath.pathname}, found ${occurrences}` + ); +} + +await writeFile(sourcePath, source.replace(vulnerablePattern, safePattern));