CodeQL alert #41 (js/incomplete-sanitization) flagged the partial escape class /[-]/g at tests/worktree-safety.test.cjs:645 — it only escaped hyphen-minus, leaving 13 other regex metacharacters (notably backslash) unescaped. The canonical class /[.*+?^${}()|[\]\\]/g is what every sibling escape in the test suite already uses (bug-2839, bug-2760, 4-phase-complete, phase6-capstone-conformance). Today dormant: the flag array is a hardcoded [a-z-] literal, so the expanded class is a no-op for the four existing flags and the regexes they produce are byte-identical. The fix prevents future drift — a contributor adding e.g. '--output=file' would have silently introduced a regex wildcard. All 69 tests in the file pass. No user-facing behavior change. Fixes #1589
72 KiB
72 KiB