Skip to content

fix(bundles): reject non-ASCII digits in SemVer identifiers - #4835

Merged
mnriem merged 1 commit into
github:mainfrom
mustafacicek-eee:fix/bundle-semver-ascii
Oct 5, 2026
Merged

mnriem merged 1 commit into
github:mainfrom
mustafacicek-eee:fix/bundle-semver-ascii

Conversation

@mustafacicek-eee

@mustafacicek-eee mustafacicek-eee commented Oct 4, 2026 •

Copy link
Copy Markdown

Description

Bundle validation currently accepts non-ASCII decimal digits in version identifiers. For example, is_semver("1.2.3-٢alpha") returns True, and specify bundle validate --offline --path bundle.yml reports a manifest with that version as valid (exit 0).

Python's \d matches Unicode decimal digits by default. SemVer 2.0.0 requires ASCII digits in its numeric identifiers and ASCII characters in prerelease identifiers. Compile the existing expression with re.ASCII so malformed bundle and component versions fail validation (exit 1). Add helper and CLI regressions for core, numeric prerelease, and alphanumeric prerelease identifiers, plus positive coverage for valid ASCII versions and the existing uppercase V prefix.

This is one validation bug fix: no new dependencies or changes to version comparison, command interfaces, or templates.

Testing

All verification below was performed by the disclosed agent on macOS with Python 3.14.8, using this checkout's own editable installation.

  • Before the fix, the two changed test modules produced 12 failed, 35 passed. All 12 failures are the new negative regressions.
  • After the fix, the same modules produced 47 passed.
  • Direct CLI reproduction: 1.2.3-٢alpha changed from valid/exit 0 to invalid/exit 1. 1.20.30-12alpha.1+build.01 remains valid/exit 0.
  • Full suite: PATH="$PWD/.venv/bin:$PATH" .venv/bin/python -m pytest tests -q → 9316 passed, 264 skipped, with network access for catalog tests. Initial invocation without the venv on PATH and without catalog connectivity had 13 failures; correcting those environment conditions cleared all failures. Skipped tests follow the suite's platform/tool requirements.
  • CI's pinned Ruff version: .venv/bin/ruff check src tests with Ruff 0.15.0 → all checks passed.
  • .venv/bin/specify --help and git diff --check passed.

AI Disclosure

Contribution submitted by @mustafacicek-eee using OpenAI Codex. The contributor requested this contribution and authorized Codex to perform the technical work and submit the PR on their behalf. Codex used GPT-6 in autonomous mode; the exact model variant and reasoning-effort setting are not exposed to the agent. Codex researched the bug and existing contributions, authored the implementation and tests, ran and inspected the verification. @mustafacicek-eee initiated this work, chose to proceed with the Spec Kit contribution, and directed its submission.

Restrict the SemVer regex to ASCII so Unicode decimal digits are rejected
in bundle and component versions. Cover valid ASCII and invalid Unicode
versions in both the version helper and the validate command.

Assisted-by: OpenAI Codex (model: GPT-6, autonomous)
@mnriem mnriem added the triage-can-wait Verdict: valid and in-scope but deprioritized; held behind the evidence gate label Oct 5, 2026
@mnriem
mnriem requested a balanced review from Copilot October 5, 2026 14:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The targeted fix is correct and includes positive, negative, helper, and CLI regression coverage.

Review effort: Balanced
Findings: None

What changed in this PR

Fixes SemVer validation to reject Unicode digits while preserving accepted ASCII versions.

Changes:

  • Compiles the SemVer regex with re.ASCII.
  • Adds helper and CLI regression coverage for valid and invalid versions.
File Description
src/​specify_cli/​bundles/​versioning.py Restricts regex digit matching to ASCII.
tests/​specify_cli/​bundles/​test_versioning.py Adds focused SemVer cases.
tests/​specify_cli/​bundles/​test_command_validate.py Adds end-to-end manifest validation cases.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@mnriem
mnriem merged commit b1463da into github:main Oct 5, 2026
15 checks passed
@mnriem

mnriem commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

triage-can-wait Verdict: valid and in-scope but deprioritized; held behind the evidence gate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants