Skip to content

fix: keep character classes within path portions - #321

Open
lprnmns wants to merge 1 commit into
isaacs:mainfrom
lprnmns:fix/make-re-path-separator-classes
Open

lprnmns wants to merge 1 commit into
isaacs:mainfrom
lprnmns:fix/make-re-path-separator-classes

Conversation

@lprnmns

@lprnmns lprnmns commented Aug 31, 2026

Copy link
Copy Markdown

Problem

makeRe() could generate a character-class regexp that matched a path separator even though minimatch() correctly treats / as a path boundary. For example, makeRe('[^a]').test('/') returned true while minimatch('/', '[^a]') returned false; the same mismatch occurred after a wildcard and with a POSIX class.

Fix

Parsed character classes now reject / at each class position. The AST start check accounts for the zero-width guard so existing dotfile and traversal protections remain unchanged.

Tests

  • npm test -- --disable-coverage -t0 test/make-re-path-separator.js - passed, 15/15
  • npm test -- -c -t0 - passed, 6,251/6,251
  • ./node_modules/.bin/oxlint src test - passed
  • ./node_modules/.bin/prettier --check src test - passed
  • git diff HEAD^ HEAD --check - passed

Compatibility

This narrows only the makeRe() false-positive path. It aligns generated regular expressions with existing per-path-portion minimatch() behavior; regex source snapshots change accordingly. No package API, dependency, or version change was made.

Related issue

Independent current-branch reproduction; no issue is linked. The final collision check found open PRs for other current minimatch defects, but none for this character-class/path-separator mismatch.

@lprnmns
lprnmns marked this pull request as ready for review August 31, 2026 14:52

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant