Website feedback: escape & so entities can't rebuild mentions; queue only lgtm comments

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
saphidandClaude Opus 5.5 committed 2026-09-28 14:39:54 +10:00
1 parent 0037b1ef4b
commit cd40a194ed
3 files changed
+10 -6

No files matched your search

+6 -5
View File
@@ -7,13 +7,14 @@ on:
issue_comment:
types: [created]
# One approval at a time, so two lgtm replies can't race on the same commit.
concurrency:
group: approve-contributor
cancel-in-progress: false
jobs:
approve:
# Only comments that might approve someone join the queue, and they run one
# at a time so two lgtm replies can't race on APPROVED_CONTRIBUTORS.
if: contains(github.event.comment.body, 'lgtm') # contains() ignores case
concurrency:
group: approve-contributor
cancel-in-progress: false
runs-on: ubuntu-latest
permissions:
contents: write
+3 -1
View File
@@ -19,10 +19,12 @@ const oneLine = (value, max) => String(value ?? "").replace(/\s+/g, " ").trim().
// Mentions in someone else's text would ping strangers, and issue references
// (#1, owner/repo#1, GH-1, github.com links) would add backlinks to other
// people's issues, so break them all with a zero-width space.
// people's issues, so break them all with a zero-width space. Escaping & first
// stops &commat; and &num; from turning back into @ and # when GitHub renders.
const ZWSP = "\u200b";
export function defang(text) {
return text
.replace(/&/g, "&amp;")
.replace(/@(?=[A-Za-z0-9])/g, `@${ZWSP}`)
.replace(/#(?=\d)/g, `#${ZWSP}`)
.replace(/\b(GH)-(?=\d)/gi, `$1${ZWSP}-`)
+1
View File
@@ -56,6 +56,7 @@ test("breaks mentions, issue refs and table cells in user text", () => {
assert.equal(defang("ping @valve about #12"), "ping @\u200bvalve about #\u200b12");
assert.equal(defang("email me@example.com"), "email me@\u200bexample.com");
assert.equal(defang("see valve/steam#7 and GH-8"), "see valve/steam#\u200b7 and GH\u200b-8");
assert.equal(defang("&commat;valve &#64;valve &num;3"), "&amp;commat;valve &amp;#\u200b64;valve &amp;num;3");
assert.equal(defang("https://github.com/a/b/issues/1"), "https://github\u200b.com/a/b/issues/1");
const issue = buildIssue(validate(form({ os: "a | b" })).value);
assert.match(issue.body, /\| a \\\| b \|/);