fix(ci): suppress Brakeman false positives for the new merge plumbing

commits_between, diff, and merge!'s update-ref call all interpolate branch refs into Open3.capture3 argv, same pattern as the rest of GitRepositoryService already covered in brakeman.ignore — Open3 never invokes a shell, and safe_rev? rejects refs starting with "-" before they reach git.

Seto Elkahfi committed Jul 5, 2026 at 11:57 UTC f5ce9a9cf1e6016e70815a94e392911bbafb85f7
1 file changed +30
config/brakeman.ignore
+30
@@ -70,6 +70,36 @@
70 "line": 245,
71 "note": "False positive: Open3.capture3 is called with a separate argument list (no shell), so the interpolated ref is passed to git as a single literal argv entry and cannot inject shell commands. GitRepositoryService.safe_rev? also rejects any ref/SHA starting with \"-\" before it reaches git, closing the git-argument-injection surface (e.g. a branch of \"--output=...\")."
72 },
73 + {
74 + "warning_type": "Command Injection",
75 + "warning_code": 14,
76 + "fingerprint": "9569afc8080f4e1e0e4b4b3de400e2695641b30574fbdb0b421d1b41c5224df1",
77 + "check_name": "Execute",
78 + "message": "Possible command injection",
79 + "file": "app/services/git_repository_service.rb",
80 + "line": 269,
81 + "note": "False positive: Open3.capture3 is called with a separate argument list (no shell), so the interpolated base/head refs are passed to git as a single literal argv entry and cannot inject shell commands. GitRepositoryService.safe_rev? also rejects any ref/SHA starting with \"-\" before it reaches git, closing the git-argument-injection surface (e.g. a branch of \"--output=...\")."
82 + },
83 + {
84 + "warning_type": "Command Injection",
85 + "warning_code": 14,
86 + "fingerprint": "03f0108aa182ee54b38be945afcbe9c90ffec86500b284510dae38fff5a2d1e0",
87 + "check_name": "Execute",
88 + "message": "Possible command injection",
89 + "file": "app/services/git_repository_service.rb",
90 + "line": 294,
91 + "note": "False positive: Open3.capture3 is called with a separate argument list (no shell), so the interpolated base/head refs are passed to git as a single literal argv entry and cannot inject shell commands. GitRepositoryService.safe_rev? also rejects any ref/SHA starting with \"-\" before it reaches git, closing the git-argument-injection surface (e.g. a branch of \"--output=...\")."
92 + },
93 + {
94 + "warning_type": "Command Injection",
95 + "warning_code": 14,
96 + "fingerprint": "405f8ed8c2a9df18ef8591501a996ad3e5ce7fb5eb046c1e1aaddd47e1dc762d",
97 + "check_name": "Execute",
98 + "message": "Possible command injection",
99 + "file": "app/services/git_repository_service.rb",
100 + "line": 336,
101 + "note": "False positive: Open3.capture3 is called with a separate argument list (no shell), so the interpolated base ref reaches `update-ref` as a single literal argv entry and cannot inject shell commands. GitRepositoryService.safe_rev? also rejects any ref/SHA starting with \"-\" before it reaches git, closing the git-argument-injection surface (e.g. a branch of \"--output=...\")."
102 + },
103 {
104 "warning_type": "Command Injection",
105 "warning_code": 14,