Repository navigation
Catch open parenthesis with no following tokens - #168
Merged
Merged
Conversation
prevents panic in cases where an open parenthesis is the last token in the stream
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
The defensive checks address the reported nil dereferences and are covered by focused regression tests.
0 open findings
What changed in this PR
Prevents parser panics on truncated SPDX expressions by returning validation errors instead.
Changes:
- Adds end-of-stream guards to parser functions.
- Reports dangling parentheses and incomplete document references.
- Adds parser and validation regression tests.
| File | Description |
|---|---|
spdxexp/parse.go |
Safely handles exhausted token streams. |
spdxexp/parse_test.go |
Tests malformed trailing tokens and operators. |
spdxexp/satisfies_test.go |
Verifies malformed licenses are rejected without panic. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This was referenced Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
closes #158
Description
prevents panic in cases where an open parenthesis is the last token in the stream
What was done
BEFORE
func parseParenthesizedExpressionchecks for an open parenthesis operator. If found, it immediately parsed an expression. If the token stream does not have any tokens remaining, this resulted in a panic.AFTER
func parseParenthesizedExpressionnow follows the parenthesis operator check with a check that more tokens are in the stream. If not, it raises an error instead of throwing a panic.