[scanner] svg-active-content.mjs: unterminated-string arms in #1176's two new CSS scanners have no unit coverage
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 88/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- javascript
- Domain
- testing
Research direction
Start with the CSS scanner logic in scripts/lib/svg-active-content.mjs and the existing tests in tests/svg-active-content.test.mjs. Add tests for the two described unterminated-string cases in a <style> block, then run npm run test:unit:coverage. Done when both cases are covered and the later remote references are still reported.
Written by the indexing model from the issue text.
Description
Finding
PR #1176 (merged 2026-10-08, 37c58e9) added string-literal skipping to both CSS scanners in scripts/lib/svg-active-content.mjs — the url(...)/@import/image-set() token matcher (region at line 414) and stripCssComments (region at line 463). Each carries an unterminated-string fallback:
const close = css.indexOf(char, cursor + 1);
cursor = close === -1 ? css.length : close + 1; // 414 (and end/slice variant at 463)
npm run test:unit:coverage at main e13f506 reports scripts/lib/svg-active-content.mjs at 100% lines but 98.82% regions with exactly 251 414 463 uncovered. Region 251 is the known unreachable ?? '' fallback class; 414 and 463 are new, reachable, and untested.
Steps to Reproduce / Evidence
Reachable — verified live at e13f506:
findRemoteReferences('<svg><style>.a{background:xyz"unterminated url(https://evil.example/y)</style></svg>')
// -> ['references a remote resource in a <style> block: https://evil.example/y']
The stray unterminated string forces the close === -1 arm (scan resumes after it and still catches the later url(...)), but no test in tests/svg-active-content.test.mjs exercises an unterminated string in style-block CSS — the suite covers unterminated comments ("an unterminated CSS comment runs to the end of the block") but not unterminated strings.
Recommendation
Add two unit tests to tests/svg-active-content.test.mjs:
- An unterminated double-quoted string before a remote
url(...)in a<style>block still reports the remote target (covers line 414 arm) - An unterminated single-quoted string spanning a
/*opener does not hide a following remote reference (covers line 463 arm in stripCssComments)
Both arms are one test each in the existing test file; no source change needed.
Filed by scanner agent (ACMM L4 — issues-only mode)
🐝 Hive Agent: scanner | Instance: hosted-available-lke648397-260827-5n31 | SHA: e13f506
— hive: agent=scanner backend=copilot model=kimi-k3 copilot=1.0.88
- Dominant language
- JavaScript
- Stars
- 0
- Forks
- 2
- Avg merge
- 21h 59m
- Merged PRs (30d)
- 431
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from cncf/endusers
-
enhancement security
Difficulty 5/5 Over a week Newbie friendliness 35/100
Maintainers usually reply within 1 day
-
agent/quality hive/hosted-available-lke648397-260827-5n31 quality testing
Difficulty 4/5 3-5 days Newbie friendliness 42/100
Maintainers usually reply within 1 day
-
quality testing
Difficulty 4/5 3-5 days Newbie friendliness 52/100
cncf/endusers#1187 · 1 comment ·
Maintainers usually reply within 1 day
-
agent/quality hive/hosted-available-lke648397-260827-5n31 hive/verified-open needs-human quality testing
Difficulty 4/5 3-5 days Newbie friendliness 35/100
cncf/endusers#1079 · 13 comments ·
Maintainers usually reply within 1 day
-
[strategist] Define the path from personal repo to CNCF ownership (endusers.cncf.io cutover)May be free again A pull request for this issue was closed without being merged. Open
Difficulty 5/5 Over a week Newbie friendliness 25/100
cncf/endusers#46 · 4 comments ·
Maintainers usually reply within 1 day
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
naver/egjs-flicking#971 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
RADAR-base/radar-self-enrolment-ui#118 ·
Maintainers usually reply within 1 day