docs: document ReDoS mitigations in JSX preprocessing #13
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🧰 Changes
Added inline documentation explaining ReDoS mitigations already implemented in the JSX preprocessing module. The original PR introduced four security fixes that eliminate catastrophic backtracking:
line 53) - Unrolling pattern(?:[^\]|\.)*` ensures each character has one match pathline 70) - Replaced regex withindexOf()for O(n) string searchline 106) - Negative lookahead(?!\/)eliminates asterisk ambiguityline 112) - Manual depth counter replaces nested quantifiersNo logic changes. Comments clarify security properties for maintainers.
🧬 QA & Testing
preprocess-jsx-expressions.test.ts)✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.