fix: restore test_llm_connection and fix additional CodeQL issues
- Restore client creation in test_llm_connection and test_embedder_connection that was incorrectly removed during CodeQL fixes - Fix CodeQL incomplete string escaping in test-backend.js (escape backslashes on Windows) - Fix CodeQL useless conditional in changelog-service.ts (use ?? instead of ||) - Fix CodeQL shell command from environment in bump-version.js (use execFileSync) Related: #1721
This commit is contained in:
@@ -77,9 +77,10 @@ async def test_llm_connection(config: "GraphitiConfig") -> tuple[bool, str]:
|
||||
Returns:
|
||||
Tuple of (success, message)
|
||||
"""
|
||||
from .factory import create_llm_client
|
||||
|
||||
try:
|
||||
# llm_client = ... # TODO: unused variable
|
||||
llm_client = create_llm_client(config)
|
||||
# Most clients don't have a ping method, so just verify creation succeeded
|
||||
return (
|
||||
True,
|
||||
@@ -103,6 +104,7 @@ async def test_embedder_connection(config: "GraphitiConfig") -> tuple[bool, str]
|
||||
Returns:
|
||||
Tuple of (success, message)
|
||||
"""
|
||||
from .factory import create_embedder
|
||||
|
||||
# First validate config
|
||||
valid, msg = validate_embedding_config(config)
|
||||
@@ -110,7 +112,7 @@ async def test_embedder_connection(config: "GraphitiConfig") -> tuple[bool, str]
|
||||
return False, msg
|
||||
|
||||
try:
|
||||
# embedder = ... # TODO: unused variable
|
||||
embedder = create_embedder(config)
|
||||
return (
|
||||
True,
|
||||
f"Embedder created successfully for provider: {config.embedder_provider}",
|
||||
|
||||
@@ -517,7 +517,7 @@ export class ChangelogService extends EventEmitter {
|
||||
} catch (error) {
|
||||
this.debug('Error in AI version suggestion, falling back to patch bump', error);
|
||||
// Fallback to patch bump if AI fails
|
||||
const version = currentVersion || '1.0.0';
|
||||
const version = currentVersion ?? '1.0.0';
|
||||
const [major, minor, patch] = version.split('.').map(Number);
|
||||
return {
|
||||
version: `${major}.${minor}.${patch + 1}`,
|
||||
|
||||
@@ -29,7 +29,7 @@
|
||||
|
||||
const fs = require('fs');
|
||||
const path = require('path');
|
||||
const { execFileSync } = require('child_process');
|
||||
const { execSync, execFileSync } = require('child_process');
|
||||
|
||||
// Colors for terminal output
|
||||
const colors = {
|
||||
@@ -243,9 +243,10 @@ function main() {
|
||||
|
||||
// 4. Validate release (check for branch/tag conflicts)
|
||||
info('Validating release...');
|
||||
// Escape version for safe shell usage
|
||||
const versionForValidation = shellescape(newVersion);
|
||||
exec(`node ${path.join(__dirname, 'validate-release.js')} v${versionForValidation}`);
|
||||
// Run validation script without spawning a shell to avoid shell interpretation of paths/args
|
||||
execFileSync('node', [path.join(__dirname, 'validate-release.js'), `v${newVersion}`], {
|
||||
stdio: 'inherit',
|
||||
});
|
||||
success('Release validation passed');
|
||||
|
||||
// 5. Update all version files
|
||||
|
||||
@@ -45,9 +45,9 @@ const args = process.argv.slice(2);
|
||||
|
||||
// Escape each argument for safe shell usage
|
||||
function escapeShellArg(arg) {
|
||||
// On Windows, escape double quotes and wrap in double quotes
|
||||
// On Windows, escape backslashes and double quotes and wrap in double quotes
|
||||
if (isWindows) {
|
||||
return `"${arg.replace(/"/g, '\\"')}"`;
|
||||
return `"${arg.replace(/\\/g, '\\\\').replace(/"/g, '\\"')}"`;
|
||||
}
|
||||
// On Unix, use single quotes and escape any single quotes in the argument
|
||||
return `'${arg.replace(/'/g, "'\\''")}'`;
|
||||
|
||||
Reference in New Issue
Block a user