You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(comments): escape repository-derived values when rendering comments
Manifest paths and sources are file paths inside the scanned repository, so
anyone who can open a pull request controls them: a directory named with link or
tag syntax, holding a manifest, put that markup into a comment posted by a trusted
integration. Alert text comes from the API. Neither is markup the CLI authored, so
both are escaped where they are interpolated -- text nodes with html.escape,
href and src with quotes escaped too, since an unescaped quote closes the
attribute and everything after it reads as more attributes.
The alert markers are the exception: they are read back verbatim when a comment is
rewritten, so they cannot be escaped without breaking the ignore round trip. They
instead lose only the ability to terminate the comment early.
plain and raw styles are untouched. Slack, Jira and the console do not render
HTML, and escaping there would show entities to a human.
Round-trip tests render a comment with each hostile path and feed it back through
the parser, because the renderer and the parser are two halves of one loop: an
escaping choice the parser cannot read would silently stop ignores working.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
<p>ℹ️ Read more on: <a href="{first_alert.purl}">This package</a> | <a href="https://socket.dev/alerts/license">What is a license policy violation?</a></p>
<p>ℹ️ Read more on: <a href="{Messages.html_attr(first_alert.purl)}">This package</a> | <a href="https://socket.dev/alerts/license">What is a license policy violation?</a></p>
1042
1086
<blockquote>
1043
1087
<p><em>Next steps:</em> Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at <strong>support@socket.dev</strong>.</p>
1044
1088
<p><em>Suggestion:</em> Find a package that does not violate your license policy or adjust your policy to allow this package's license.</p>
0 commit comments