You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Incomplete coverage.print() is sanitized, but print_table() still writes API-controlled values directly via console.log(). (e.g. discover titles and URLs). Please audit other direct console.log/error and stdout/stderr.write paths, and sanitize untrusted values before applying CLI styling (e.g. success/warn/info/fail functions).
Do not sanitize non-TTY stdout. The current change makes -o file preserve escapes while > file and pipes strip them, potentially corrupting raw/CSV/MD/HTML output. Sanitize only when is_tty. Please also transform is_tty to function (const is_tty = () => process.stdout.isTTY === true;) because currently it's not a live check and tests can't flip it after import. This constant is used in other files (spinner.ts, discover.ts, scraper.ts), so it needs to be updated there as well.
Add tests for:
sanitized TTY output
preserved piped/redirected output
malicious values passed through print_table()
Also stripVTControlCharacters() doesn't handle standalone controls such as \r, \b, \x07.
Suggested:
Normalize carriage return before applying the character class.
In print_table(), sanitize and flatten cells before computing widths to not break table alignment.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.