Repository navigation
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 30 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (6)
ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Free Run ID: 📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThis change adds the Changesprintf Format Expansion Rule
Estimated code review effort: 2 (Simple) | ~15 minutes Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 3 systems. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
dc55d80 to
bd2c99b
Compare
bd2c99b to
4817da4
Compare
4817da4 to
1020958
Compare
2a609a9 to
a259163
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Option parsing misses dynamic formats when -- follows either form of the -v option.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds a ShellCheck SC2059-inspired rule preventing dynamic printf format strings.
Changes:
- Implements and registers the recommended rule.
- Adds rule and plugin tests.
- Documents usage, examples, and configuration.
| File | Description |
|---|---|
src/rules/no-variables-in-printf-format.ts |
Implements format-string detection. |
src/rules/no-variables-in-printf-format.spec.ts |
Tests rule behavior. |
src/index.ts |
Registers and enables the rule. |
src/index.spec.ts |
Verifies rule exposure. |
README.md |
Adds the rule to the catalog. |
docs/rules/no-variables-in-printf-format.md |
Documents the rule. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
@copilot address the review comments. Be sure to add tests. |
a26459c to
afa74da
Compare
44866a6 to
c941e24
Compare
c941e24 to
bc81359
Compare
bc81359 to
e770362
Compare
e770362 to
2174268
Compare
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: nzakas <38546+nzakas@users.noreply.github.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2174268 to
034ef0f
Compare

Adds
shell/no-variables-in-printf-format, which mirrors ShellCheck SC2059: a variable in theprintfformat string is interpreted as a format, so%or\in the data breaks output. Useprintf '%s' "$var"instead.Behavior
-v var,-vvar, or--. Reports it if it contains a parameter expansion or command substitution, quoted or not.$((...))) in the format aren't checked either."error".Documentation
Adds
docs/rules/no-variables-in-printf-format.md, following the format of the@eslint/json,@eslint/css, and@eslint/markdownrule docs: description, background, rule details with incorrect and correct examples, options, when not to use it, and the ShellCheck reference. The rule'smeta.docs.urlpoints at that file, and its README table entry links to it.Testing
10 RuleTester cases and 5 documentation checks (322 total); build, lint, and format checks pass.
🤖 Generated with Claude Code
Stack created with GitHub Stacks CLI • Give Feedback 💬
Summary by CodeRabbit
printfformat strings, helping prevent unexpected formatting or escape sequences.