Skip to content

Conversation

@Uday111-ai
Copy link

This PR addresses two issues:

Security/Bug Fix: The regex used to parse GitHub URLs in
gfi/populate.py
was flawed. It used a character class [...] instead of a group
(...)
for the protocol, and lacked a start/end anchor. This allowed invalid URLs (e.g., notgithub.com) to pass validation.

Fix: Updated GH_URL_PATTERN to r"^(?:https?://)?github.com/(?P[\w.-]+)/(?P[\w.-]+)/?$"
Data Consistency: The
data/repositories.toml
file had an inconsistent entry with a protocol prefix.

Fix: Removed https:// from the entry for pyupio/safety to match the project convention.

Verification:

Validated the new regex against various test cases (valid and invalid URLs).
Verified that
gfi/test_data.py
passes with the changes.

@vercel
Copy link

vercel bot commented Dec 19, 2025

@Uday111-ai is attempting to deploy a commit to the DeepSource Team on Vercel.

A member of the Team first needs to authorize it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant