What happens
src/readme-editor.ts, getTokenIndexes:
const startRegExp = new RegExp(startTokenFormat.replace('%s', token));
const stopRegExp = new RegExp(endTokenFormat.replace('%s', token));
The token is inserted raw. Any regex metacharacter in it changes the pattern.
Example in this repo
README.md and README.example.md carry <!-- start [.github/ghadocs/examples/] --> markers. In the pattern, [...] becomes a character class and . matches any character, so those markers can never match themselves.
Impact today
None reachable: every name in README_SECTIONS is plain letters. It becomes live the moment a section name carries ., [, ( or similar, and scripts/verify-readme-contract.mjs builds its patterns the same way.
Suggested direction
Escape the token before building the pattern, in the editor and in the verifier alike.
What happens
src/readme-editor.ts,getTokenIndexes:The token is inserted raw. Any regex metacharacter in it changes the pattern.
Example in this repo
README.mdandREADME.example.mdcarry<!-- start [.github/ghadocs/examples/] -->markers. In the pattern,[...]becomes a character class and.matches any character, so those markers can never match themselves.Impact today
None reachable: every name in
README_SECTIONSis plain letters. It becomes live the moment a section name carries.,[,(or similar, andscripts/verify-readme-contract.mjsbuilds its patterns the same way.Suggested direction
Escape the token before building the pattern, in the editor and in the verifier alike.