From f737859e5c6d033db2b72582b167c5865b9f99a9 Mon Sep 17 00:00:00 2001 From: Klaus Lungwitz Date: Thu, 5 Mar 2026 13:00:35 -0300 Subject: [PATCH] fix(ci): loop HTML comment removal to prevent incomplete sanitization Fixes CodeQL alert #119 (js/incomplete-multi-character-sanitization). --- .github/scripts/set-pr-status.js | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/.github/scripts/set-pr-status.js b/.github/scripts/set-pr-status.js index 0d496e18527..cec06b3de17 100644 --- a/.github/scripts/set-pr-status.js +++ b/.github/scripts/set-pr-status.js @@ -151,7 +151,12 @@ module.exports = async ({ github, context }) => { // Gets all issue numbers that would be closed if the PR is merged. function extractLinkedIssueNumbers(prBody) { const body = prBody || ""; - const withoutComments = body.replace(//g, ""); + let withoutComments = body; + let previous; + do { + previous = withoutComments; + withoutComments = withoutComments.replace(//g, ""); + } while (withoutComments !== previous); const matches = [...withoutComments.matchAll(/(?:close[sd]?|fixe[sd]?|resolve[sd]?)\s+#(\d+)/gi)]; return matches.map(match => parseInt(match[1], 10)); }