From 5765f8d1900e01026458caca361bc94040a9dc89 Mon Sep 17 00:00:00 2001 From: teknium1 <127238744+teknium1@users.noreply.github.com> Date: Wed, 23 Sep 2026 19:51:52 -0700 Subject: [PATCH] =?UTF-8?q?fix(plugins):=20desktop=20lint=20masks=20a=20ne?= =?UTF-8?q?w=20RegExp("").source`, a real injection through .source — desktop_surface_findings returned 0 findings for that line. The literal is now masked only when the constructor is the argument of .replace/.replaceAll/.split/.match/.matchAll/.search or the receiver of .test/.exec; every other use (.source, .toString(), template interpolation) is a string-builder and keeps firing. The existing test gains the .source line (must flag) and a .test() line (must not). --- hermes_cli/plugin_validate_desktop.py | 12 +++++++++--- tests/hermes_cli/test_plugin_validate.py | 5 +++++ website/docs/user-guide/features/plugin-catalog.md | 8 +++++--- 3 files changed, 19 insertions(+), 6 deletions(-) diff --git a/hermes_cli/plugin_validate_desktop.py b/hermes_cli/plugin_validate_desktop.py index 2ee8f9415e..b11d7c0c56 100644 --- a/hermes_cli/plugin_validate_desktop.py +++ b/hermes_cli/plugin_validate_desktop.py @@ -43,15 +43,21 @@ _COMMENT = re.compile(r"/\*.*?\*/|(?").source``) the constructor is +# a string-builder and its literal keeps firing. _REGEX_LITERAL = re.compile(r"(? str: masked = _REGEX_LITERAL.sub(lambda m: " " * len(m.group(0)), source) - return _REGEXP_CTOR_PATTERN.sub(lambda m: " " * len(m.group(0)), masked) + return _REGEXP_CTOR_MATCHER.sub(lambda m: " " * len(m.group(0)), masked) def desktop_surface_findings(source: str) -> List[Tuple[str, int]]: diff --git a/tests/hermes_cli/test_plugin_validate.py b/tests/hermes_cli/test_plugin_validate.py index 5e3aea7c03..672c39129a 100644 --- a/tests/hermes_cli/test_plugin_validate.py +++ b/tests/hermes_cli/test_plugin_validate.py @@ -294,15 +294,20 @@ class TestDesktopSurface: "const tag = document.createElement('script'); tag.src = 'https://evil.example/x.js'; document.head.append(tag)\n" "const dyn = html.replace(new RegExp(\"\", flags), '')\n" "el.innerHTML = new RegExp('x') && ''\n" + "el.innerHTML = new RegExp(\"\").source\n" + "if (new RegExp(\"