Skip to content

Potential fix for code scanning alert no. 10: Uncontrolled command line - #57

Closed
Ritual-Dev-Git wants to merge 1 commit into
mainfrom
alert-autofix-10
Closed

Ritual-Dev-Git wants to merge 1 commit into
mainfrom
alert-autofix-10

Conversation

@Ritual-Dev-Git

Copy link
Copy Markdown
Collaborator

Potential fix for https://github.com/RitualDev-Lab/DevShelf/security/code-scanning/10

The safest fix is to stop using child_process.exec with a concatenated command string and instead use child_process.spawn (or execFile) with argument arrays and shell: false. This prevents shell interpretation of attacker-controlled characters.
In bin/cli.js, update the import at line 16 from exec to spawn, and rewrite openUrl(url) (lines 45–54) to invoke platform-specific executables with argument arrays:

  • macOS: spawn("open", [url], { shell: false, detached: true, stdio: "ignore" })
  • Linux/other: spawn("xdg-open", [url], ...)
  • Windows: use cmd.exe /c start "" <url> via spawn(process.env.comspec || "cmd.exe", ["/c", "start", "", url], { shell: false, ... }) so the shell is not spawned by Node directly through exec and no interpolated shell string is built.

Also detach and unref() to preserve the current non-blocking CLI behavior.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🛡️ DevShelf PR Validation Report

⚠️ Action Required: Formatting or Duplicate Issues Detected

Please review and address the findings below before this PR can be merged:

❌ Schema & Validation Errors

File Resource Field Issue
ai-tools.json Promptfoo description Description contains placeholder or incomplete text.

🔄 Duplicate Detection Warnings

Incoming Resource Target URL Existing Match Existing File Match Type
Vercel Link Vercel for Open Source perks.json same_domain
Netlify Link Netlify for Open Source perks.json same_domain
MongoDB Atlas Link MongoDB for Startups perks.json same_domain

Note: If this tool is an entirely new separate product hosted on the same domain, please leave a comment explaining why.


💡 Tip: You can use the DevShelf Contribution Wizard to generate error-free JSON.

🤖 DevShelf AI-Driven PR Optimization & Tagging

Automated Heuristic Analyzer • Add GEMINI_API_KEY for LLM enhancement.

📦 Resource: Open-Meteo

  • Target File: shelf/apis.json
  • Suggested Category: Weather & Climate.json
  • Recommended Tags: [100% Free Tier] [No Auth Required]

📝 Description Refinement

  • Original: "Free weather forecast API for commercial and non-commercial use with hourly forecasts and historical weather data."
  • ✨ Suggested: "Free weather forecast API for commercial and non-commercial use with hourly forecasts and historical weather data."

📋 Ready-to-Merge JSON Block

{
  "name": "Open-Meteo",
  "url": "https://open-meteo.com",
  "category": "Weather & Climate",
  "description": "Free weather forecast API for commercial and non-commercial use with hourly forecasts and historical weather data.",
  "auth": "No Key",
  "cors": "Yes",
  "rateLimit": "10,000 req/day",
  "https": true,
  "statusTags": [
    "[100% Free Tier]",
    "[No Auth Required]"
  ],
  "section": "Weather & Climate"
}

💡 Contributors can copy the JSON block above directly into their PR to ensure pristine catalog formatting.

Comment thread bin/cli.js
Comment on lines +49 to +53
const child = spawn(process.env.comspec || "cmd.exe", ["/c", "start", "", url], {
detached: true,
stdio: "ignore",
shell: false,
});
@Ritual-Dev-Git
Ritual-Dev-Git marked this pull request as ready for review October 2, 2026 11:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants