Skip to content

fix: inspect TypeScript declaration content - #601

Open
efegokdemir wants to merge 1 commit into
NVIDIA:mainfrom
efegokdemir:codex/issue-585-declaration-executable
Open

efegokdemir wants to merge 1 commit into
NVIDIA:mainfrom
efegokdemir:codex/issue-585-declaration-executable

Conversation

@efegokdemir

Copy link
Copy Markdown

Summary

Fixes #585 by distinguishing clearly inert TypeScript declaration files from executable TypeScript based on their content, while keeping uncertain files executable.

Changes

  • Recognize .d.ts, .d.cts, and .d.mts declaration names only when their UTF-8 content is clearly declaration-only.
  • Keep empty, binary, undecidable, and runtime-bearing declaration-named files executable.
  • Add regression coverage for inert declarations and a require() payload hidden behind a .d.cts name.

Testing

  • uv run pytest tests/nodes/test_nested_artifacts.py -q — 47 passed, 1 warning.
  • uv run ruff check src/ tests/ — passed.
  • uv run ruff format --check src/ tests/ — passed.
  • git diff --check — passed.
  • uv run pytest -m 'not integration and not provider' tests/ -q — started successfully and reached 61% before being interrupted after several minutes; no failures were reported before interruption.

Notes

The implementation is intentionally fail-closed: declaration filenames alone never suppress executable classification. This PR was prepared with AI assistance; I reviewed the change and take responsibility for the submitted code.

Signed-off-by: Efe Gökdemir <efe@rexcode.co.uk>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Declaration files classify as executable, but excluding .d.cts/.d.mts by name is unsafe

1 participant