Skip to content

fix(scripts): backticks in a double-quoted echo run as command substitution - #492

Merged
hyperpolymath merged 11 commits into
mainfrom
fix/shellcheck-parse-error
Sep 14, 2026
Merged

hyperpolymath merged 11 commits into
mainfrom
fix/shellcheck-parse-error

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Line 19 wrapped an example in backticks inside a double-quoted string. Backticks there are COMMAND SUBSTITUTION, so bash tried to execute '+ uses: …@' and printed the message with the example silently deleted. Switched to single quotes. Same defect class as hyperpolymath/Axiom.jl#82.

Found by an estate-wide shellcheck sweep of 5,111 tracked scripts across 375 repos. This file was one of 11 that fail to parse (SC1073/SC1072) — shellcheck stops analysing at the failure, so everything after it was never checked either.

Verified: shellcheck -S error now reports 0 findings for this file.

…tution

Line 19 wrapped an example in backticks inside a double-quoted string. Backticks there are COMMAND SUBSTITUTION, so bash tried to execute '+ uses: …@<sha>' and printed the message with the example silently deleted. Switched to single quotes. Same defect class as hyperpolymath/Axiom.jl#82.

Found by an estate-wide shellcheck sweep of 5,111 tracked scripts across 375
repos. This file was one of 11 that fail to PARSE (SC1073/SC1072) — shellcheck
stops analysing at the failure, so anything after it was never checked either.

Verified: shellcheck -S error now reports 0 findings for this file.
@coderabbitai

coderabbitai Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 8f3a47ea-d4c5-47ba-ae9d-609ceb0cab97

📥 Commits

Reviewing files that changed from the base of the PR and between 90e2512 and c3314c0.

📒 Files selected for processing (1)
  • bots/seambot/tests/github_integration.rs

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (7)
  • GitHub Check: CodeQL
  • GitHub Check: governance / Validate Hypatia Baseline
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: build · test · clippy (robot-repo-automaton)
  • GitHub Check: build · test · clippy (shared-context)
  • GitHub Check: analyze (actions, none)
  • GitHub Check: build · test · clippy (dashboard)
⚠️ CI failures not shown inline (4)

GitHub Actions: Dogfood Gate / 1_Groove manifest check.txt: fix(scripts): backticks in a double-quoted echo run as command substitution

Conclusion: failure

View job details

##[group]Run # Check for static or dynamic Groove endpoints
 �[36;1m# Check for static or dynamic Groove endpoints�[0m
 �[36;1mHAS_MANIFEST="false"�[0m
 �[36;1mHAS_GROOVE_CODE="false"�[0m
 �[36;1m�[0m
 �[36;1mif [ -f ".well-known/groove/manifest.json" ]; then�[0m
 �[36;1m  HAS_MANIFEST="true"�[0m
 �[36;1m  # Validate the manifest JSON�[0m
 �[36;1m  if ! jq empty .well-known/groove/manifest.json 2>/dev/null; then�[0m
 �[36;1m    echo "::error file=.well-known/groove/manifest.json::Invalid JSON in Groove manifest"�[0m

GitHub Actions: Dogfood Gate / Groove manifest check: fix(scripts): backticks in a double-quoted echo run as command substitution

Conclusion: failure

View job details

##[group]Run # Check for static or dynamic Groove endpoints
 �[36;1m# Check for static or dynamic Groove endpoints�[0m
 �[36;1mHAS_MANIFEST="false"�[0m
 �[36;1mHAS_GROOVE_CODE="false"�[0m
 �[36;1m�[0m
 �[36;1mif [ -f ".well-known/groove/manifest.json" ]; then�[0m
 �[36;1m  HAS_MANIFEST="true"�[0m
 �[36;1m  # Validate the manifest JSON�[0m
 �[36;1m  if ! jq empty .well-known/groove/manifest.json 2>/dev/null; then�[0m
 �[36;1m    echo "::error file=.well-known/groove/manifest.json::Invalid JSON in Groove manifest"�[0m

GitHub Actions: Dogfood Gate / 4_Validate A2ML manifests.txt: fix(scripts): backticks in a double-quoted echo run as command substitution

Conclusion: failure

View job details

##[group]GITHUB_TOKEN Permissions
 Actions: read
 Contents: read
 Metadata: read
 ##[endgroup]
 Secret source: Actions
 Cache mode: write
 Using locked action versions from the workflow's lockfile
 Prepare workflow directory
 Prepare all required actions
 Getting action download info
 ##[error]Unable to resolve action `hyperpolymath/a2ml-ecosystem`: the repository has been renamed or transferred. Run `gh actions-lock` to update the lockfile. lockfile verification did not produce a result for this action

GitHub Actions: Dogfood Gate / Validate A2ML manifests: fix(scripts): backticks in a double-quoted echo run as command substitution

Conclusion: failure

View job details

##[group]GITHUB_TOKEN Permissions
 Actions: read
 Contents: read
 Metadata: read
 ##[endgroup]
 Secret source: Actions
 Cache mode: write
 Using locked action versions from the workflow's lockfile
 Prepare workflow directory
 Prepare all required actions
 Getting action download info
 ##[error]Unable to resolve action `hyperpolymath/a2ml-ecosystem`: the repository has been renamed or transferred. Run `gh actions-lock` to update the lockfile. lockfile verification did not produce a result for this action
🔇 Additional comments (1)
bots/seambot/tests/github_integration.rs (1)

154-154: LGTM!


📝 Summary

Summary by CodeRabbit

  • Bug Fixes
    • Improved informational messages for pull requests without SHA-pinned action additions, ensuring backticks are displayed literally and no unintended command substitution occurs.
  • Tests
    • Updated installation-token test coverage with a shorter representative token while preserving validation of the expected format and parsing behaviour.

Walkthrough

The obsolete pull request script now preserves literal backticks in its skip message. The GitHub integration test now uses a shorter concrete installation token fixture. No control flow or public declarations changed.

Changes

Maintenance updates

Layer / File(s) Summary
Skip message quoting
scripts/fix-close-obsolete-pr.sh
The no-pinned-uses: skip message now emits literal backticks. Bash no longer attempts command substitution.
Installation token fixture
bots/seambot/tests/github_integration.rs
The test fixture now uses ghs_test-token and retains the existing prefix and parsing assertions.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to c3314

The changes preserve the literal shell message and update only a test token fixture, with no remaining merge-blocking risk.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the shell-script fix for unintended command substitution caused by backticks in a double-quoted echo.
Description check ✅ Passed The description directly explains the command-substitution defect, the fix, and the ShellCheck validation.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
⚔️ Resolve merge conflicts 💡
  • Resolve merge conflict in branch fix/shellcheck-parse-error
🛠️ Fix failing CI checks
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit sees backticks stay still
The shell prints each mark by will
A test token takes a shorter trail
Its ghs_ prefix does not fail
Small changes pass the checking gate

Comment @coderabbitai help to get the list of available commands.

@gitar-bot

This comment has been minimized.

coderabbitai[bot]
coderabbitai Bot previously approved these changes Aug 26, 2026
@codacy-production

codacy-production Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

@codacy-production codacy-production Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

The PR correctly identifies and addresses a command substitution bug in scripts/fix-close-obsolete-pr.sh where backticks within double quotes were being executed. However, the current solution of switching to single quotes has triggered a new ShellCheck warning, resulting in the PR being flagged as not up to standards by Codacy.

To resolve this and satisfy the linter while maintaining the fix, the backticks should be escaped within double quotes. Additionally, there is a lack of automated or manual verification scenarios provided in the code to ensure the output remains correct after these changes.

Test suggestions

  • Execute the script with a PR diff containing no matching lines and verify the output is 'SKIP: PR has no + uses: …@<sha> lines' without shell execution errors.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Execute the script with a PR diff containing no matching lines and verify the output is 'SKIP: PR has no `+ uses: …@<sha>` lines' without shell execution errors.

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Comment thread scripts/fix-close-obsolete-pr.sh Outdated
Co-authored-by: codacy-production[bot] <61871480+codacy-production[bot]@users.noreply.github.com>
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
coderabbitai[bot]
coderabbitai Bot previously approved these changes Aug 26, 2026
@hyperpolymath
hyperpolymath enabled auto-merge (squash) August 28, 2026 07:49
@gitguardian

gitguardian Bot commented Sep 4, 2026

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
36740420 Triggered Generic Password b84e2f0 bots/cipherbot/src/analyzers/infra.rs View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Nothing to fix from this PR. All 4 failing check(s) are already failing on main, so they aren't caused by your changes.

⏭️ 4 check(s) skipped — already failing on `main` (not caused by this PR)
  • GitHub Actions: Hypatia Security Scan / 0_hypatia _ Hypatia Neurosymbolic Analysis.txt
  • GitHub Actions: Hypatia Security Scan / hypatia _ Hypatia Neurosymbolic Analysis
  • GitHub Actions: Hypatia Security Scan / hypatia _ Hypatia Neurosymbolic Analysis
  • GitHub Actions: Hypatia Security Scan / hypatia _ Hypatia Neurosymbolic Analysis

These need to be addressed on main (or by whoever owns them), not in this PR.

Replace the credential-shaped GitHub installation token fixture with
`ghs_test-token` so CI security and governance checks do not mistake
test data for a secret.

Validation: `git diff --check` passed; tests were not run.

[View coding
task](https://app.coderabbit.ai/code/tasks/3ed9558f-b037-4b12-a554-f284f8c8da8e?source=coding_agent_github_pr_description)

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
coderabbitai[bot]
coderabbitai Bot previously approved these changes Sep 13, 2026
@coderabbitai

coderabbitai Bot commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Completed: Resolve merge conflicts in PR #492 — View commit 769b890

Resolved conflicts in:
- bots/seambot/tests/github_integration.rs (unmerged)

Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
CodeRabbit-Task-Id: f69c464e-26a4-4aef-a799-57b026bdce44
@hyperpolymath
hyperpolymath enabled auto-merge (squash) September 14, 2026 02:03
@hyperpolymath
hyperpolymath merged commit 236b77e into main Sep 14, 2026
15 of 17 checks passed
@hyperpolymath
hyperpolymath deleted the fix/shellcheck-parse-error branch September 14, 2026 02:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant