Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Shell-quote source IDs in caseworkctl BReg package recovery commands

Open Beginner friendly
#1,729 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
88/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
rust
Domain
cli

Research direction

Start in crates/registry-caseworkctl/src/breg_package.rs, focusing on caseworkctl check --against-breg-package and the existing shell_word uses for project and package paths. Pass the source ID through shell_word in both recovery commands, then add and run a unit test using an ID with whitespace and a shell metacharacter. Done means copied commands preserve the source ID as one literal argument.

Written by the indexing model from the issue text.

Description

area:casework bug criticality:p3 triage:needs-implementation

Problem

caseworkctl check --against-breg-package builds recovery commands (the recheck command and repin_command) with an unquoted --source-id. CaseworkProject::check only requires a source ID to be non-empty and unique, so an ID containing whitespace or shell metacharacters yields a command that the shell splits or interprets when an operator copies it.

Fix direction

Pass the source ID through the existing shell_word helper, as the project and package paths already are, and add a unit test with a source ID containing a space and a metacharacter.

Raised by the Codex review on #1718 (crates/registry-caseworkctl/src/breg_package.rs).

Dominant language
Rust
Stars
2
Forks
0
Avg merge
7h 22m
Merged PRs (30d)
213

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from registrystack/registry-stack

All issues in registrystack/registry-stack

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.