Skip to content

feat: add no-variables-in-printf-format rule - #13

Open
nzakas wants to merge 3 commits into
rule/require-cd-guardfrom
rule/no-variables-in-printf-format
Open

nzakas wants to merge 3 commits into
rule/require-cd-guardfrom
rule/no-variables-in-printf-format

Conversation

@nzakas

@nzakas nzakas commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

Adds shell/no-variables-in-printf-format, which mirrors ShellCheck SC2059: a variable in the printf format string is interpreted as a format, so % or \ in the data breaks output. Use printf '%s' "$var" instead.

Behavior

  • Finds the format argument, skipping -v var, -vvar, or --. Reports it if it contains a parameter expansion or command substitution, quoted or not.
  • Not reported: static formats, and variables in the data arguments after the format. Arithmetic expansions ($((...))) in the format aren't checked either.
  • No autofix: rewriting the format needs to know what the data contains.
  • Recommended config: "error".

Documentation

Adds docs/rules/no-variables-in-printf-format.md, following the format of the @eslint/json, @eslint/css, and @eslint/markdown rule docs: description, background, rule details with incorrect and correct examples, options, when not to use it, and the ShellCheck reference. The rule's meta.docs.url points at that file, and its README table entry links to it.

Testing

10 RuleTester cases and 5 documentation checks (322 total); build, lint, and format checks pass.

🤖 Generated with Claude Code


Stack created with GitHub Stacks CLI • Give Feedback 💬

Summary by CodeRabbit

  • New Features
    • Added a recommended rule that flags variable or command substitutions in printf format strings, helping prevent unexpected formatting or escape sequences.
    • Added documentation with examples, rule behavior, and guidance on disabling it.

@coderabbitai

coderabbitai Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 30 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 76c48559-292c-49e7-a661-07db992d7546
📥 Commits

Reviewing files that changed from the base of the PR and between afa74da and 034ef0f.

📒 Files selected for processing (6)
  • README.md
  • docs/rules/no-variables-in-printf-format.md
  • src/index.spec.ts
  • src/index.ts
  • src/rules/no-variables-in-printf-format.spec.ts
  • src/rules/no-variables-in-printf-format.ts
ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Free

Run ID: 5c2b3d81-4704-4543-b6ac-4c79c6c3bad7

📥 Commits

Reviewing files that changed from the base of the PR and between 8437b3a and a26459c.

📒 Files selected for processing (6)
  • README.md
  • docs/rules/no-variables-in-printf-format.md
  • src/index.spec.ts
  • src/index.ts
  • src/rules/no-variables-in-printf-format.spec.ts
  • src/rules/no-variables-in-printf-format.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

This change adds the no-variables-in-printf-format rule. It reports expansions in the printf format argument and is enabled as an error in the recommended configuration.

Changes

printf Format Expansion Rule

Layer / File(s) Summary
Detect expansions in printf formats
src/rules/no-variables-in-printf-format.ts, src/rules/no-variables-in-printf-format.spec.ts
The rule reports variable or command-substitution expansions in the format argument, including quoted expansions. It handles -v var, -vvar, and --; tests cover these cases and valid inputs.
Register and document the rule
src/index.ts, src/index.spec.ts, README.md, docs/rules/no-variables-in-printf-format.md
The plugin registers the rule and enables it in the recommended configuration. The rule list and documentation describe SC2059 and the rule’s checked argument and excluded cases.

Estimated code review effort: 2 (Simple) | ~15 minutes

Architecture Summary

Architecture risk: 🔵 Low · up to a2645

The change affects 3 systems.

Changed systems: src, docs, README.md

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — src (service) was modified; 4 changed files map to changed impact.
  • observed — docs (service) was modified; 1 changed file maps to changed impact.
  • observed — README.md (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in README.md: Added the no-variables-in-printf-format entry to the Rules table, identifying SC2059 and marking the rule as recommended at error severity.
  • observed — Modified behavior in docs/rules/no-variables-in-printf-format.md: Adds documentation describing the rule’s checked format-argument position and expansion types, excluded cases, examples, lack of options, and a case for disabling the rule.
  • observed — Modified behavior in src/index.spec.ts: The expected rule ID list now includes no-variables-in-printf-format.
  • observed — Modified behavior in src/index.ts: Imports the noVariablesInPrintfFormat rule implementation.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@nzakas
nzakas added this pull request to stack #16 September 18, 2026 15:00
@nzakas
nzakas marked this pull request as ready for review September 18, 2026 15:02
@nzakas
nzakas force-pushed the rule/no-variables-in-printf-format branch from dc55d80 to bd2c99b Compare September 18, 2026 19:01
@nzakas
nzakas force-pushed the rule/no-variables-in-printf-format branch from bd2c99b to 4817da4 Compare September 22, 2026 19:56
@nzakas
nzakas force-pushed the rule/no-variables-in-printf-format branch from 4817da4 to 1020958 Compare September 22, 2026 20:24
@nzakas
nzakas force-pushed the rule/no-variables-in-printf-format branch 2 times, most recently from 2a609a9 to a259163 Compare September 22, 2026 21:21
@nzakas
nzakas requested a balanced review from Copilot September 28, 2026 18:25

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Option parsing misses dynamic formats when -- follows either form of the -v option.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds a ShellCheck SC2059-inspired rule preventing dynamic printf format strings.

Changes:

  • Implements and registers the recommended rule.
  • Adds rule and plugin tests.
  • Documents usage, examples, and configuration.
File Description
src/​rules/​no-variables-in-printf-format.ts Implements format-string detection.
src/​rules/​no-variables-in-printf-format.spec.ts Tests rule behavior.
src/​index.ts Registers and enables the rule.
src/​index.spec.ts Verifies rule exposure.
README.md Adds the rule to the catalog.
docs/​rules/​no-variables-in-printf-format.md Documents the rule.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/rules/no-variables-in-printf-format.ts
@nzakas

nzakas commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

@copilot address the review comments. Be sure to add tests.

Copilot AI commented Sep 29, 2026

Copy link
Copy Markdown

@copilot address the review comments. Be sure to add tests.

Fixed in a26459c: the rule now skips an optional -- after both -v name and -vname. Added regression tests for dynamic and static formats; all 296 tests, build, lint, and format checks pass.

@nzakas
nzakas force-pushed the rule/no-variables-in-printf-format branch from a26459c to afa74da Compare October 1, 2026 18:07
@nzakas
nzakas force-pushed the rule/no-variables-in-printf-format branch from 44866a6 to c941e24 Compare October 2, 2026 16:05
@nzakas
nzakas force-pushed the rule/no-variables-in-printf-format branch from c941e24 to bc81359 Compare October 2, 2026 16:18
@nzakas
nzakas force-pushed the rule/no-variables-in-printf-format branch from bc81359 to e770362 Compare October 6, 2026 19:09
@nzakas
nzakas force-pushed the rule/no-variables-in-printf-format branch from e770362 to 2174268 Compare October 6, 2026 19:26
nzakas and others added 3 commits October 6, 2026 15:35
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: nzakas <38546+nzakas@users.noreply.github.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@nzakas
nzakas force-pushed the rule/no-variables-in-printf-format branch from 2174268 to 034ef0f Compare October 6, 2026 19:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants