Skip to content

Conversation

@p-linnane
Copy link
Member

Potential fix for https://github.com/Homebrew/homebrew-core/security/code-scanning/173

To fix the problem, we should ensure that both backslashes and @ characters are properly escaped in the string interpolation. This means replacing every backslash (\) with a double backslash (\\), and every @ with \@. The best way to do this is to use gsub twice: first to escape backslashes, then to escape @. This should be done in the string interpolation on line 94, within the s.gsub! call. No additional imports or dependencies are needed, as this is standard Ruby string manipulation.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

@github-actions github-actions bot added autosquash Automatically squash pull request commits according to Homebrew style. legacy Relates to a versioned @ formula formula deprecated Formula deprecated icu4c ICU use is a significant feature of the PR or issue labels Aug 5, 2025
Potential fix for code scanning alert no. 173: Incomplete string escaping or encoding

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

Signed-off-by: Patrick Linnane <patrick@linnane.io>
@github-actions github-actions bot removed the autosquash Automatically squash pull request commits according to Homebrew style. label Aug 5, 2025
@p-linnane p-linnane changed the title Potential fix for code scanning alert no. 173: Incomplete string escaping or encoding php@8.1: Fix incomplete string escaping or encoding Aug 5, 2025
@p-linnane p-linnane marked this pull request as ready for review August 5, 2025 16:52
@carlocab carlocab added CI-no-bottles Merge without publishing bottles and removed CI-no-bottles Merge without publishing bottles labels Aug 5, 2025
@github-actions
Copy link
Contributor

github-actions bot commented Aug 6, 2025

🤖 An automated task has requested bottles to be published to this PR.

Caution

Please do not push to this PR branch before the bottle commits have been pushed, as this results in a state that is difficult to recover from. If you need to resolve a merge conflict, please use a merge commit. Do not force-push to this PR branch.

@github-actions github-actions bot added the CI-published-bottle-commits The commits for the built bottles have been pushed to the PR branch. label Aug 6, 2025
@BrewTestBot BrewTestBot enabled auto-merge August 6, 2025 12:10
@BrewTestBot BrewTestBot added this pull request to the merge queue Aug 6, 2025
Merged via the queue into main with commit dbfb743 Aug 6, 2025
22 checks passed
@BrewTestBot BrewTestBot deleted the alert-autofix-173 branch August 6, 2025 12:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI-published-bottle-commits The commits for the built bottles have been pushed to the PR branch. formula deprecated Formula deprecated icu4c ICU use is a significant feature of the PR or issue legacy Relates to a versioned @ formula

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants