Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Update brace-expansion security fix
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
  • Loading branch information
brunoborges and Copilot committed Aug 4, 2026
commit b5c6639b25fb4fb66124f1cc6085d13a901f2dc6
34 changes: 30 additions & 4 deletions dist/cleanup/767.index.js
Original file line number Diff line number Diff line change
Expand Up @@ -59543,7 +59543,7 @@ function combine(acc, pre, values, max, maxLength, dropEmpties) {
}
// The expansion values of a single numeric (`1..5`) or alphabetic (`a..e..2`)
// sequence body.
function expandSequence(body, isAlphaSequence, max) {
function expandSequence(body, isAlphaSequence, max, maxLength) {
const n = body.split(/\.\./);
const N = [];
// A sequence body always splits into two or three parts, but the compiler
Expand All @@ -59566,6 +59566,7 @@ function expandSequence(body, isAlphaSequence, max) {
test = gte;
}
const pad = n.some(isPadded);
let length = 0;
for (let i = x; test(i, y) && N.length < max; i += incr) {
let c;
if (isAlphaSequence) {
Expand All @@ -59589,7 +59590,10 @@ function expandSequence(body, isAlphaSequence, max) {
}
}
}
if (length + c.length > maxLength)
break;
N.push(c);
length += c.length;
}
return N;
}
Expand Down Expand Up @@ -59643,7 +59647,7 @@ function expand_(str, max, maxLength, isTop) {
}
let values;
if (isSequence) {
values = expandSequence(m.body, isAlphaSequence, max);
values = expandSequence(m.body, isAlphaSequence, max, maxLength);
}
else {
let n = parseCommaParts(m.body);
Expand All @@ -59661,9 +59665,31 @@ function expand_(str, max, maxLength, isTop) {
}
/* c8 ignore stop */
}
// Values that `combine` is going to drop as empty produce no result, so
// they must not count against `max` - otherwise `{a,,b}` with `max: 2`
// would stop at `['a', '']` and yield one result instead of two. Skipping
// them outright keeps `values` bounded while leaving `max` a bound on
// *kept* results.
let dropsEmpties = dropEmpties && !m.post.length && !pre;
for (let d = 0; dropsEmpties && d < acc.length; d++) {
if (acc[d]) {
dropsEmpties = false;
}
}
values = [];
for (let j = 0; j < n.length; j++) {
values.push.apply(values, expand_(n[j], max, maxLength, false));
let valuesLength = 0;
outer: for (let j = 0; j < n.length; j++) {
const expanded = expand_(n[j], max, maxLength, false);
for (let k = 0; k < expanded.length; k++) {
const v = expanded[k];
if (dropsEmpties && !v)
continue;
if (values.length >= max || valuesLength + v.length > maxLength) {
break outer;
}
values.push(v);
valuesLength += v.length;
}
}
}
acc = combine(acc, pre, values, max, maxLength, dropEmpties && !m.post.length);
Expand Down
34 changes: 30 additions & 4 deletions dist/setup/971.index.js
Original file line number Diff line number Diff line change
Expand Up @@ -52531,7 +52531,7 @@ function combine(acc, pre, values, max, maxLength, dropEmpties) {
}
// The expansion values of a single numeric (`1..5`) or alphabetic (`a..e..2`)
// sequence body.
function expandSequence(body, isAlphaSequence, max) {
function expandSequence(body, isAlphaSequence, max, maxLength) {
const n = body.split(/\.\./);
const N = [];
// A sequence body always splits into two or three parts, but the compiler
Expand All @@ -52554,6 +52554,7 @@ function expandSequence(body, isAlphaSequence, max) {
test = gte;
}
const pad = n.some(isPadded);
let length = 0;
for (let i = x; test(i, y) && N.length < max; i += incr) {
let c;
if (isAlphaSequence) {
Expand All @@ -52577,7 +52578,10 @@ function expandSequence(body, isAlphaSequence, max) {
}
}
}
if (length + c.length > maxLength)
break;
N.push(c);
length += c.length;
}
return N;
}
Expand Down Expand Up @@ -52631,7 +52635,7 @@ function expand_(str, max, maxLength, isTop) {
}
let values;
if (isSequence) {
values = expandSequence(m.body, isAlphaSequence, max);
values = expandSequence(m.body, isAlphaSequence, max, maxLength);
}
else {
let n = parseCommaParts(m.body);
Expand All @@ -52649,9 +52653,31 @@ function expand_(str, max, maxLength, isTop) {
}
/* c8 ignore stop */
}
// Values that `combine` is going to drop as empty produce no result, so
// they must not count against `max` - otherwise `{a,,b}` with `max: 2`
// would stop at `['a', '']` and yield one result instead of two. Skipping
// them outright keeps `values` bounded while leaving `max` a bound on
// *kept* results.
let dropsEmpties = dropEmpties && !m.post.length && !pre;
for (let d = 0; dropsEmpties && d < acc.length; d++) {
if (acc[d]) {
dropsEmpties = false;
}
}
values = [];
for (let j = 0; j < n.length; j++) {
values.push.apply(values, expand_(n[j], max, maxLength, false));
let valuesLength = 0;
outer: for (let j = 0; j < n.length; j++) {
const expanded = expand_(n[j], max, maxLength, false);
for (let k = 0; k < expanded.length; k++) {
const v = expanded[k];
if (dropsEmpties && !v)
continue;
if (values.length >= max || valuesLength + v.length > maxLength) {
break outer;
}
values.push(v);
valuesLength += v.length;
}
}
}
acc = combine(acc, pre, values, max, maxLength, dropEmpties && !m.post.length);
Expand Down
6 changes: 3 additions & 3 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading