Skip to content

Commit ffccca6

Browse files
committed
fix(audits): check require() specifiers and keep path resolution inside the repo
1 parent 30e80f9 commit ffccca6

1 file changed

Lines changed: 6 additions & 2 deletions

File tree

‎scripts/check-guidance-refs.ts‎

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -120,8 +120,12 @@ function isPlaceholder(ref: string): boolean {
120120
return /[<>{}*$]|\.\.\.|…|\bfoo\b|\bxxx?\b/i.test(ref)
121121
}
122122

123+
/** A file or directory inside the repo; a path escaping the root never resolves. */
123124
function resolvesFrom(base: string, ref: string): boolean {
124-
return SOURCE_EXTENSIONS.some((ext) => existsSync(path.join(base, `${ref}${ext}`)))
125+
return SOURCE_EXTENSIONS.some((ext) => {
126+
const candidate = path.resolve(base, `${ref}${ext}`)
127+
return !path.relative(ROOT, candidate).startsWith('..') && existsSync(candidate)
128+
})
125129
}
126130

127131
const MODULE_CANDIDATES = [
@@ -285,7 +289,7 @@ function auditDocument(relFile: string, workspaces: Workspaces, files: string[])
285289
for (const match of text.matchAll(REPO_PATH)) checkPath(line, trimProse(match[1]))
286290
if (inFence) {
287291
// Example code: only imports are concrete enough to check.
288-
if (/\b(?:from|import|mock|vi\.mock|doMock)\b/.test(text)) {
292+
if (/\b(?:from|import|require|mock|vi\.mock|doMock)\b/.test(text)) {
289293
for (const match of text.matchAll(IMPORT_SPEC)) checkPath(line, match[2])
290294
}
291295
return

0 commit comments

Comments
 (0)