Skip to content

Reject trailing terminators in provider candidates - #6

Merged
dataforxyz merged 1 commit into
mainfrom
fix/protected-provider-canonical-regex
Jul 30, 2026
Merged

dataforxyz merged 1 commit into
mainfrom
fix/protected-provider-canonical-regex

Conversation

@dataforxyz

Copy link
Copy Markdown
Owner

Summary

Reject CR, LF, U+2028, and U+2029 suffixes in protected-provider semantic versions and require provider digest length to be exactly 64 before regex validation.

JavaScript $ accepts before a final line terminator; this closes that canonicalization gap.

Verification

  • commit 6f8c069
  • exact hotfix diff SHA-256 9f0972fb477380b2f97432d5d35264e44258e83ac88095fb6da90301aad8c853
  • residual hostile review: APPROVED
  • focused 9/9; full 204/204; typecheck/diff pass

@dataforxyz
dataforxyz merged commit ea1c5b5 into main Jul 30, 2026
2 checks passed
@dataforxyz
dataforxyz deleted the fix/protected-provider-canonical-regex branch July 30, 2026 19:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant