fix(ci): suppress Brakeman false positives for the new merge plumbing
commits_between, diff, and merge!'s update-ref call all interpolate branch refs into Open3.capture3 argv, same pattern as the rest of GitRepositoryService already covered in brakeman.ignore — Open3 never invokes a shell, and safe_rev? rejects refs starting with "-" before they reach git.
Seto Elkahfi committed
Jul 5, 2026 at 11:57 UTC
f5ce9a9cf1e6016e70815a94e392911bbafb85f7
1 file changed
+30
config/brakeman.ignore
+30
@@ -70,6 +70,36 @@
70
"line": 245,
71
"note": "False positive: Open3.capture3 is called with a separate argument list (no shell), so the interpolated ref is passed to git as a single literal argv entry and cannot inject shell commands. GitRepositoryService.safe_rev? also rejects any ref/SHA starting with \"-\" before it reaches git, closing the git-argument-injection surface (e.g. a branch of \"--output=...\")."
72
},
73
+ {
74
+ "warning_type": "Command Injection",
75
+ "warning_code": 14,
76
+ "fingerprint": "9569afc8080f4e1e0e4b4b3de400e2695641b30574fbdb0b421d1b41c5224df1",
77
+ "check_name": "Execute",
78
+ "message": "Possible command injection",
79
+ "file": "app/services/git_repository_service.rb",
80
+ "line": 269,
81
+ "note": "False positive: Open3.capture3 is called with a separate argument list (no shell), so the interpolated base/head refs are passed to git as a single literal argv entry and cannot inject shell commands. GitRepositoryService.safe_rev? also rejects any ref/SHA starting with \"-\" before it reaches git, closing the git-argument-injection surface (e.g. a branch of \"--output=...\")."
82
+ },
83
+ {
84
+ "warning_type": "Command Injection",
85
+ "warning_code": 14,
86
+ "fingerprint": "03f0108aa182ee54b38be945afcbe9c90ffec86500b284510dae38fff5a2d1e0",
87
+ "check_name": "Execute",
88
+ "message": "Possible command injection",
89
+ "file": "app/services/git_repository_service.rb",
90
+ "line": 294,
91
+ "note": "False positive: Open3.capture3 is called with a separate argument list (no shell), so the interpolated base/head refs are passed to git as a single literal argv entry and cannot inject shell commands. GitRepositoryService.safe_rev? also rejects any ref/SHA starting with \"-\" before it reaches git, closing the git-argument-injection surface (e.g. a branch of \"--output=...\")."
92
+ },
93
+ {
94
+ "warning_type": "Command Injection",
95
+ "warning_code": 14,
96
+ "fingerprint": "405f8ed8c2a9df18ef8591501a996ad3e5ce7fb5eb046c1e1aaddd47e1dc762d",
97
+ "check_name": "Execute",
98
+ "message": "Possible command injection",
99
+ "file": "app/services/git_repository_service.rb",
100
+ "line": 336,
101
+ "note": "False positive: Open3.capture3 is called with a separate argument list (no shell), so the interpolated base ref reaches `update-ref` as a single literal argv entry and cannot inject shell commands. GitRepositoryService.safe_rev? also rejects any ref/SHA starting with \"-\" before it reaches git, closing the git-argument-injection surface (e.g. a branch of \"--output=...\")."
102
+ },
103
{
104
"warning_type": "Command Injection",
105
"warning_code": 14,