Skip to content

fix(analyzer): recognize JavaScript template literals - #801

Open
efegokdemir wants to merge 1 commit into
NVIDIA:mainfrom
efegokdemir:codex/skill-694-js-template
Open

efegokdemir wants to merge 1 commit into
NVIDIA:mainfrom
efegokdemir:codex/skill-694-js-template

Conversation

@efegokdemir

Copy link
Copy Markdown
Contributor

What

Recognize parser-proven JavaScript template literal spans when checking whether the bounded shell parser exhausted its input. Benign templates no longer make an otherwise complete JavaScript file appear partially inspected. Malformed or unsupported JavaScript remains on the conservative path. When an interpolated template coexists with a recognized shell-execution call, the file also remains partial because this analyzer does not prove the template's data flow.

Why

JavaScript uses backticks to delimit template literals. The shell parser treated those delimiters and quotes inside interpolations as shell syntax, so ordinary source files could receive static_parse_limit and never reach a complete inspection result.

How

Use Esprima to parse complete JavaScript within the existing source-size bound and obtain exact template-literal ranges. The static finding scan still receives the original source, so command findings remain visible. Template ownership is used only for parser-completeness accounting, and dynamic templates in files with recognized execution calls retain the conservative result.

This addresses the JavaScript template-literal case in #694; the broader issue remains open for its other reported language cases.

Testing

  • On pristine upstream/main, the four benign template regression cases failed as expected; after this change they pass. Dynamic execution and malformed-source controls remain partial.
  • pytest -m 'not integration and not provider' tests/ -q: 10,544 passed, 17 skipped, 4 xfailed, 133 deselected.
  • Focused parser/ownership suites: 300 passed after the final change.
  • make lint, make format-check, and uv build --out-dir /tmp/skillspector-694-dist passed.
  • mypy src/skillspector/javascript_tokens.py passed.

Compatibility

No public API changes. Static findings continue to scan the original source. The new parser fails closed for unsupported syntax and incomplete contexts.

Checklist

  • Added regression coverage for benign templates, dynamic execution, malformed source, and ledger outcomes.
  • Signed off the commit under the DCO.
  • Added SPDX headers to the new source and test files.

Prepared with AI assistance.

Related to #694.

Signed-off-by: Efe <efe@rexcode.co.uk>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant