Conversation
<!-- agent --> Address `GHSA-m64x-33q8-m5h7` in the shared `parse_actor_and_date()` helper used for commit authors, committers, and annotated taggers. Malformed metadata could make its regular expressions retry overlapping field boundaries and consume excessive CPU time before returning. Bound the leading field name at its first separator and check the line ending once, before extracting the actor and date. The date expression then needs no trailing wildcard or end assertion. Apply the same field boundary to the actor-only fallback. This prevents repeated scans while preserving accepted suffixes, Unicode digits, final newlines, and the existing zero-date fallback for malformed input. Add compatibility cases and CPU-time regressions for long malformed metadata and multiline input, covering all three field names and long valid names. Both timing regressions failed before the fix and pass afterward. A separate comparison preserved capture groups in 3,240 cases. Git reference: `git/git@d38352cd43ab9745686d697872408bc3249a153f`, `ident.c:split_ident_line()` and `t/t4212-log-corrupt.sh`, which scan identity delimiters directly and cover tolerant handling of invalid dates. Retain GitPython's existing return values for malformed input. Assisted-by: GPT 6.0 Co-authored-by: GPT 6.0 <codex@openai.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Correct the failing parser expectation and add the required 3.2.1 release URL.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
This pull request hardens actor and date parsing against malformed or oversized metadata while preserving existing behavior.
Changes:
- Replaces vulnerable regexes with bounded parsing patterns.
- Adds compatibility and performance regression tests.
- Documents the security advisory.
| File | Summary |
|---|---|
test/test_util.py |
Adds parser behavior and performance tests; one expected fallback requires correction. |
git/objects/util.py |
Updates actor/date parsing regexes. |
doc/source/changes.rst |
Records the security advisory; requires the forthcoming 3.2.1 release URL. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Tasks
This section is for Byron only. Models continuing this PR must not add, remove, check, uncheck, rename, or reorder checkboxes here.
Everything below this line was generated by
Codex GPT-6.Created by Codex on behalf of Byron. Byron will review before this is ready to merge.
Bound parsing work for malformed actor metadata in the shared helper used by commit authors, committers, and annotated taggers. Preserve existing parsed values, accepted suffixes, and malformed-date fallbacks. Add compatibility and performance regression coverage.
Advisory summary
GHSA-m64x-33q8-m5h7: medium severity, affecting the
GitPythonpackage on PyPI (<= 3.1.62). The advisory currently lists no patched version or CVE identifier.Validation
git diff --checkpassed.b386c177found no actionable issues and independently checked capture groups across 97,656 inputs.Git behavior reference:
git/git@d38352cd43ab9745686d697872408bc3249a153f,ident.c:split_ident_line()andt/t4212-log-corrupt.sh, for delimiter scanning and tolerant handling of invalid dates.