From cd56500d2064471d15b82cb3e306800395ae38f1 Mon Sep 17 00:00:00 2001 From: Tom Boucher Date: Mon, 22 Jun 2026 14:07:33 -0400 Subject: [PATCH] test: complete regex-escape class in worktree-safety assertion (#1589) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CodeQL alert #41 (js/incomplete-sanitization) flagged the partial escape class /[-]/g at tests/worktree-safety.test.cjs:645 — it only escaped hyphen-minus, leaving 13 other regex metacharacters (notably backslash) unescaped. The canonical class /[.*+?^${}()|[\]\\]/g is what every sibling escape in the test suite already uses (bug-2839, bug-2760, 4-phase-complete, phase6-capstone-conformance). Today dormant: the flag array is a hardcoded [a-z-] literal, so the expanded class is a no-op for the four existing flags and the regexes they produce are byte-identical. The fix prevents future drift — a contributor adding e.g. '--output=file' would have silently introduced a regex wildcard. All 69 tests in the file pass. No user-facing behavior change. Fixes #1589 --- tests/worktree-safety.test.cjs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/worktree-safety.test.cjs b/tests/worktree-safety.test.cjs index c5020e4bd..fad859975 100644 --- a/tests/worktree-safety.test.cjs +++ b/tests/worktree-safety.test.cjs @@ -642,7 +642,7 @@ describe('planWorktreeRecordAgent', () => { }); assert.equal(plan.reason, 'missing_field'); for (const flag of ['--agent-id', '--path', '--branch', '--base']) { - assert.match(plan.hint, new RegExp(flag.replace(/[-]/g, '\\$&'))); + assert.match(plan.hint, new RegExp(flag.replace(/[.*+?^${}()|[\]\\]/g, '\\$&'))); } });