fix: restore test_llm_connection and fix additional CodeQL issues

- Restore client creation in test_llm_connection and test_embedder_connection
  that was incorrectly removed during CodeQL fixes
- Fix CodeQL incomplete string escaping in test-backend.js (escape backslashes on Windows)
- Fix CodeQL useless conditional in changelog-service.ts (use ?? instead of ||)
- Fix CodeQL shell command from environment in bump-version.js (use execFileSync)

Related: #1721
This commit is contained in:
StillKnotKnown
2026-02-09 12:31:38 +02:00
parent 66b1185b9b
commit 8f6a9b160b
4 changed files with 12 additions and 9 deletions
@@ -77,9 +77,10 @@ async def test_llm_connection(config: "GraphitiConfig") -> tuple[bool, str]:
Returns:
Tuple of (success, message)
"""
from .factory import create_llm_client
try:
# llm_client = ... # TODO: unused variable
llm_client = create_llm_client(config)
# Most clients don't have a ping method, so just verify creation succeeded
return (
True,
@@ -103,6 +104,7 @@ async def test_embedder_connection(config: "GraphitiConfig") -> tuple[bool, str]
Returns:
Tuple of (success, message)
"""
from .factory import create_embedder
# First validate config
valid, msg = validate_embedding_config(config)
@@ -110,7 +112,7 @@ async def test_embedder_connection(config: "GraphitiConfig") -> tuple[bool, str]
return False, msg
try:
# embedder = ... # TODO: unused variable
embedder = create_embedder(config)
return (
True,
f"Embedder created successfully for provider: {config.embedder_provider}",
@@ -517,7 +517,7 @@ export class ChangelogService extends EventEmitter {
} catch (error) {
this.debug('Error in AI version suggestion, falling back to patch bump', error);
// Fallback to patch bump if AI fails
const version = currentVersion || '1.0.0';
const version = currentVersion ?? '1.0.0';
const [major, minor, patch] = version.split('.').map(Number);
return {
version: `${major}.${minor}.${patch + 1}`,
+5 -4
View File
@@ -29,7 +29,7 @@
const fs = require('fs');
const path = require('path');
const { execFileSync } = require('child_process');
const { execSync, execFileSync } = require('child_process');
// Colors for terminal output
const colors = {
@@ -243,9 +243,10 @@ function main() {
// 4. Validate release (check for branch/tag conflicts)
info('Validating release...');
// Escape version for safe shell usage
const versionForValidation = shellescape(newVersion);
exec(`node ${path.join(__dirname, 'validate-release.js')} v${versionForValidation}`);
// Run validation script without spawning a shell to avoid shell interpretation of paths/args
execFileSync('node', [path.join(__dirname, 'validate-release.js'), `v${newVersion}`], {
stdio: 'inherit',
});
success('Release validation passed');
// 5. Update all version files
+2 -2
View File
@@ -45,9 +45,9 @@ const args = process.argv.slice(2);
// Escape each argument for safe shell usage
function escapeShellArg(arg) {
// On Windows, escape double quotes and wrap in double quotes
// On Windows, escape backslashes and double quotes and wrap in double quotes
if (isWindows) {
return `"${arg.replace(/"/g, '\\"')}"`;
return `"${arg.replace(/\\/g, '\\\\').replace(/"/g, '\\"')}"`;
}
// On Unix, use single quotes and escape any single quotes in the argument
return `'${arg.replace(/'/g, "'\\''")}'`;