From 2b82a8bc3a16045b2e77927d2c15fdfb7402143b Mon Sep 17 00:00:00 2001 From: Arunesh Dwivedi Date: Tue, 28 Jul 2026 10:45:06 +0000 Subject: [PATCH] fix: prevent nil pointer panic in parseOperator when no tokens remain Fixes issue #158: panic: nil-pointer dereference when parsing a dangling open parenthesis The peek() function can return nil when there are no more tokens. Accessing token.role on a nil pointer causes a panic. Added nil check before accessing token fields. --- spdxexp/parse.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/spdxexp/parse.go b/spdxexp/parse.go index f66de71..1e37567 100644 --- a/spdxexp/parse.go +++ b/spdxexp/parse.go @@ -361,7 +361,7 @@ func (t *tokenStream) parseLicense() *node { // Advances the index if the operator is found. func (t *tokenStream) parseOperator(operator string) *string { token := t.peek() - if token.role == operatorToken && token.value == operator { + if token != nil && token.role == operatorToken && token.value == operator { t.next() return &(token.value) }