e5edfd576d2bbd1c885750f94c57704b61894801

Author
Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Committer
GitHub <noreply@github.com>
Date

Message

sec: update git-module (#742)

The regex solution proposed in #737 is not sufficient.
I've added `--end-of-options` to the relevant commands in https://github.com/aymanbagabas/git-module/pull/1
so this reverts changes made in #737 and update git-module to include that fix.

Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>

Diff

 1diff --git a/go.mod b/go.mod
 2index bd2daf1fb7534ffff6863901a791bf7254e47275..f9f8a616c895daacf89d80916ec54018e50a2ab4 100644
 3--- a/go.mod
 4+++ b/go.mod
 5@@ -2,20 +2,10 @@ module github.com/charmbracelet/soft-serve
 6 
 7 go 1.23.0
 8 
 9-require (
10-	github.com/dustin/go-humanize v1.0.1
11-	github.com/go-git/go-git/v5 v5.16.2
12-	github.com/matryer/is v1.4.1
13-	github.com/muesli/reflow v0.3.0
14-)
15-
16 require (
17 	github.com/alecthomas/chroma/v2 v2.20.0
18 	github.com/aymanbagabas/bubblezone/v2 v2.0.0-20250319214444-bb232f16d5e3
19-)
20-
21-require (
22-	github.com/aymanbagabas/git-module v1.8.4-0.20231101154130-8d27204ac6d2
23+	github.com/aymanbagabas/git-module v1.8.4-0.20250826192401-1f81c5471e53
24 	github.com/caarlos0/duration v0.0.0-20240108180406-5d492514f3c7
25 	github.com/caarlos0/env/v11 v11.3.1
26 	github.com/charmbracelet/bubbles/v2 v2.0.0-beta.1.0.20250603123720-56bbc4a1ba66
27@@ -29,6 +19,8 @@ require (
28 	github.com/charmbracelet/ssh v0.0.0-20250128164007-98fd5ae11894
29 	github.com/charmbracelet/wish/v2 v2.0.0-20250505151211-5996fc7c1f33
30 	github.com/charmbracelet/x/ansi v0.9.3
31+	github.com/dustin/go-humanize v1.0.1
32+	github.com/go-git/go-git/v5 v5.16.2
33 	github.com/go-jose/go-jose/v3 v3.0.4
34 	github.com/gobwas/glob v0.2.3
35 	github.com/golang-jwt/jwt/v5 v5.3.0
36@@ -39,7 +31,9 @@ require (
37 	github.com/hashicorp/golang-lru/v2 v2.0.7
38 	github.com/jmoiron/sqlx v1.4.0
39 	github.com/lib/pq v1.10.9
40+	github.com/matryer/is v1.4.1
41 	github.com/muesli/mango-cobra v1.2.0
42+	github.com/muesli/reflow v0.3.0
43 	github.com/muesli/roff v0.1.0
44 	github.com/prometheus/client_golang v1.22.0
45 	github.com/robfig/cron/v3 v3.0.1
46diff --git a/go.sum b/go.sum
47index e2fd78897f55932d73ab371f7ff0b905574d982f..7db080262ba6db4a53d24f3073ae5f3a7d4bff24 100644
48--- a/go.sum
49+++ b/go.sum
50@@ -12,8 +12,8 @@ github.com/atotto/clipboard v0.1.4 h1:EH0zSVneZPSuFR11BlR9YppQTVDbh5+16AmcJi4g1z
51 github.com/atotto/clipboard v0.1.4/go.mod h1:ZY9tmq7sm5xIbd9bOK4onWV4S6X0u6GY7Vn0Yu86PYI=
52 github.com/aymanbagabas/bubblezone/v2 v2.0.0-20250319214444-bb232f16d5e3 h1:1z2ihw0YUYUhNmRaavyXvG9ZU/9Tj0vj6sA3z5DFIJ8=
53 github.com/aymanbagabas/bubblezone/v2 v2.0.0-20250319214444-bb232f16d5e3/go.mod h1:sJwqZoo/BSKSizmr0pSJ758RuRsnjlkrOaxPtwlWtOs=
54-github.com/aymanbagabas/git-module v1.8.4-0.20231101154130-8d27204ac6d2 h1:3w5KT+shE3hzWhORGiu2liVjEoaCEXm9uZP47+Gw4So=
55-github.com/aymanbagabas/git-module v1.8.4-0.20231101154130-8d27204ac6d2/go.mod h1:d4gQ7/3/S2sPq4NnKdtAgUOVr6XtLpWFtxyVV5/+76U=
56+github.com/aymanbagabas/git-module v1.8.4-0.20250826192401-1f81c5471e53 h1:KfKp+gVsQtuM9qb8Putvkx1jjAWqlvI1vdv5x9hdFoQ=
57+github.com/aymanbagabas/git-module v1.8.4-0.20250826192401-1f81c5471e53/go.mod h1:d4gQ7/3/S2sPq4NnKdtAgUOVr6XtLpWFtxyVV5/+76U=
58 github.com/aymanbagabas/go-udiff v0.2.0 h1:TK0fH4MteXUDspT88n8CKzvK0X9O2xu9yQjWpi6yML8=
59 github.com/aymanbagabas/go-udiff v0.2.0/go.mod h1:RE4Ex0qsGkTAJoQdQQCA0uG+nAzJO/pI/QwceO5fgrA=
60 github.com/aymerick/douceur v0.2.0 h1:Mv+mAeH1Q+n9Fr+oyamOlAkUNPWPlA8PPGR0QAaYuPk=
61diff --git a/pkg/ssh/cmd/commit.go b/pkg/ssh/cmd/commit.go
62index 1d99d299aaa549d186679e9236007d138881977f..ad2020d36a2076e540f71c3eba380909fd7756b9 100644
63--- a/pkg/ssh/cmd/commit.go
64+++ b/pkg/ssh/cmd/commit.go
65@@ -2,7 +2,6 @@ package cmd
66 
67 import (
68 	"fmt"
69-	"regexp"
70 	"strings"
71 	"time"
72 
73@@ -14,8 +13,6 @@ import (
74 	"github.com/spf13/cobra"
75 )
76 
77-var shaRE = regexp.MustCompile(`^[a-fA-F0-9]{5,40}$`)
78-
79 // commitCommand returns a command that prints the contents of a commit.
80 func commitCommand() *cobra.Command {
81 	var color bool
82@@ -32,10 +29,6 @@ func commitCommand() *cobra.Command {
83 			repoName := args[0]
84 			commitSHA := args[1]
85 
86-			if !shaRE.MatchString(commitSHA) {
87-				return fmt.Errorf("invalid commit SHA: %s", commitSHA)
88-			}
89-
90 			rr, err := be.Repository(ctx, repoName)
91 			if err != nil {
92 				return err