5a2bde5882610b0ba08bf8d9cf339fe2c487e665

Author
Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Committer
GitHub <noreply@github.com>
Date

Message

fix: check that commit is a SHA1 (#737)

Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>

Diff

 1diff --git a/pkg/ssh/cmd/commit.go b/pkg/ssh/cmd/commit.go
 2index ad2020d36a2076e540f71c3eba380909fd7756b9..1d99d299aaa549d186679e9236007d138881977f 100644
 3--- a/pkg/ssh/cmd/commit.go
 4+++ b/pkg/ssh/cmd/commit.go
 5@@ -2,6 +2,7 @@ package cmd
 6 
 7 import (
 8 	"fmt"
 9+	"regexp"
10 	"strings"
11 	"time"
12 
13@@ -13,6 +14,8 @@ import (
14 	"github.com/spf13/cobra"
15 )
16 
17+var shaRE = regexp.MustCompile(`^[a-fA-F0-9]{5,40}$`)
18+
19 // commitCommand returns a command that prints the contents of a commit.
20 func commitCommand() *cobra.Command {
21 	var color bool
22@@ -29,6 +32,10 @@ func commitCommand() *cobra.Command {
23 			repoName := args[0]
24 			commitSHA := args[1]
25 
26+			if !shaRE.MatchString(commitSHA) {
27+				return fmt.Errorf("invalid commit SHA: %s", commitSHA)
28+			}
29+
30 			rr, err := be.Repository(ctx, repoName)
31 			if err != nil {
32 				return err