Repository navigation
Feat: Investigate more license edge cases - #15
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review infoConfiguration used: defaults Review profile: CHILL Plan: Pro 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughAdds logic to resolve installed filesystem paths from npm/pnpm lockfile package keys and attaches resolved paths to dependency nodes; includes tests asserting resolved top-level and nested dependency paths and ensuring paths that traverse outside the lock directory are not resolved. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~8 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 2 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@src/runners/lockfileGraph.ts`:
- Around line 656-660: The resolveNpmInstalledPath function currently joins
normalizedKey segments into lockDir without guarding against path traversal;
validate the normalizedKey segments (from normalizeLockPackageKey) to reject any
segment equal to ".." or that is an absolute path, then build a safe path via
path.resolve(lockDir, ...segments) and verify the resulting resolved path is
contained within lockDir (e.g. ensure path.relative(lockDir, resolved) does not
start with '..'); if validation fails return undefined. Update
resolveNpmInstalledPath to use these checks and return undefined for any
traversal/absolute-segment case.
ℹ️ Review info
Configuration used: defaults
Review profile: CHILL
Plan: Pro
⛔ Files ignored due to path filters (2)
dist/runners/lockfileGraph.jsis excluded by!**/dist/**dist/utils.jsis excluded by!**/dist/**
📒 Files selected for processing (2)
src/runners/lockfileGraph.tssrc/runners/npmLs.test.ts
|
Note Docstrings generation - SUCCESS |
Docstrings generation was requested by @JosephMaynard. The following files were modified: * `src/runners/lockfileGraph.ts` These files were ignored: * `src/runners/npmLs.test.ts`
Summary by CodeRabbit
New Features
Tests