-
-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Description
Not sure if this is supposed to be funny but the release notes file for 2.26
contain right-to-left override (RLO) unicode characters for one of the contributors, sigh (rl-2.26.md#L115).
I get that it is just documentation in markdown, but these kinds of things get flagged now by security vulnerability scanners... Also it completely messes up the formatting of the entire line (I guess it should end with a PDF character not another RLO to limit the effect...;-)
It gets flagged in Fedora package update automated test results:
[BAD] A forbidden code point, 0x202E, was found in the nix-2.31.2/doc/manual/source/release-notes/rl-2.26.md source file on line 115 at column 2. This source file is used by nix.spec. [Security]
The github blame and code views of the file also flag that that the line contains hidden unicode characters:
with a tooltip This line has hidden Unicode characters.
Perhaps I can open a PR to remove these characters? I see they come from @dwt's github name.
Anyway I will filter them out of the Fedora package.