Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

False positive: js/incomplete-hostname-regexp treats LinkifyIt.match(text) as a regex call

Open
#22,546 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
55/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
javascript
Domain
security

Research direction

Inspect the js/incomplete-hostname-regexp query and its library models, then compare the Sinon precedent in PR 19854. Re-run the linked CodeQL alert against test/link-recognition-qualification.test.js; done when LinkifyIt.match(text) literals are no longer reported while ordinary String.match regex findings remain enabled.

Written by the indexing model from the issue text.

Description

Description of the false positive

js/incomplete-hostname-regexp treats the argument to LinkifyIt.match(text) as a regular expression. The receiver is a LinkifyIt instance from linkify-it@6.1.0; its argument is document text to scan for links, not a regex pattern. Literal dots in these URLs are therefore correct.

Observed with CodeQL 2.26.4, JavaScript/TypeScript analysis, build-mode: none, and github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938 (v4.37.9), using the default query suite without custom queries or exclusions.

Diagnostic on the text literal:

This string, which is used as a regular expression here, has an unescaped '.' before 'youtube.com/watc', so it might match more hosts than expected.

The linked use is scanner.match(text).

Code samples or links to source code

Small excerpt retaining the constructor, configuration, literal and call from the reported test:

import { LinkifyIt } from "linkify-it";

const scanner = new LinkifyIt({ fuzzyLink: false, fuzzyEmail: false })
  .add("ftp:", null)
  .add("mailto:", null)
  .add("//", null);
const text =
  "😀 *literal* (https://www.youtube.com/watch?v=tax4e4hBBZc), then https://store.steampowered.com/app/457140/.";
const matches = scanner.match(text);
console.log(matches.map((m) => m.raw));

With linkify-it@6.1.0, the API returns matches for the two literal URLs. The package's build/index.d.ts declares match(text: string): Match[] | null; build/index.mjs implements the method by scanning that document text with the library's link recognizers.

Exact reported source at the PR merge revision.

Source at the immutable PR head.

Validation: node --test test/link-recognition-qualification.test.js passes 1/1, including exact URL and offset assertions. The hosted CodeQL analysis reports the finding in the linked full test. The reduced excerpt above has not been separately analyzed with CodeQL; no claim is made that it is the smallest scanner reproducer.

Expected: recognize that this imported library's match method consumes document text, so these literals should not be classified as hostname regular expressions. Ordinary String.match regex findings should remain enabled.

Related precedent: https://github.com/github/codeql/pull/19854 explicitly models Sinon's match calls as non-RegExp. I found no existing linkify-it report in the upstream search.

URL to the alert on GitHub code scanning (optional)

https://github.com/MaksymShostak/steam-community-bbcode/security/code-scanning/2

Failing PR check.

Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 16h
Merged PRs (30d)
143

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/codeql

All issues in github/codeql

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.