From f35a86ff70fbc89d03811c821689c7e6c0536899 Mon Sep 17 00:00:00 2001 From: Mike McQuaid Date: Wed, 2 Nov 2016 15:57:19 -0400 Subject: [PATCH] audit: stricter test system calls check. Ensure that the name is suffixed with whitespace or quotes. --- Library/Homebrew/dev-cmd/audit.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Library/Homebrew/dev-cmd/audit.rb b/Library/Homebrew/dev-cmd/audit.rb index 32ff14de18..df068c99f3 100644 --- a/Library/Homebrew/dev-cmd/audit.rb +++ b/Library/Homebrew/dev-cmd/audit.rb @@ -735,7 +735,7 @@ class FormulaAuditor end bin_names.each do |name| ["system", "shell_output", "pipe_output"].each do |cmd| - if text =~ /(def test|test do).*#{cmd}[\(\s]+['"]#{name}/m + if text =~ /(def test|test do).*#{cmd}[\(\s]+['"]#{name}[\s'"]/m problem %(fully scope test #{cmd} calls e.g. #{cmd} "\#{bin}/#{name}") end end