Ignore:
Timestamp:
09/19/26 10:30:30 (10 days ago)
Author:
Klimentina Efremova <klimentina08642@…>
Branches:
finki-main, main
Children:
06ebe74
Parents:
62b2964
Message:

Turned database from SQLite to PostgressSQL, updated database changes from Phase 1 and 2

File:
1 edited

Legend:

Unmodified
Added
Removed
  • node_modules/minimatch/README.md

    r62b2964 r33517cc  
    77It works by converting glob expressions into JavaScript `RegExp`
    88objects.
     9
     10## Important Security Consideration!
     11
     12> [!WARNING] 
     13> This library uses JavaScript regular expressions. Please read
     14> the following warning carefully, and be thoughtful about what
     15> you provide to this library in production systems.
     16
     17_Any_ library in JavaScript that deals with matching string
     18patterns using regular expressions will be subject to
     19[ReDoS](https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS)
     20if the pattern is generated using untrusted input.
     21
     22Efforts have been made to mitigate risk as much as is feasible in
     23such a library, providing maximum recursion depths and so forth,
     24but these measures can only ultimately protect against accidents,
     25not malice. A dedicated attacker can _always_ find patterns that
     26cannot be defended against by a bash-compatible glob pattern
     27matching system that uses JavaScript regular expressions.
     28
     29To be extremely clear:
     30
     31> [!WARNING] 
     32> **If you create a system where you take user input, and use
     33> that input as the source of a Regular Expression pattern, in
     34> this or any extant glob matcher in JavaScript, you will be
     35> pwned.**
     36
     37A future version of this library _may_ use a different matching
     38algorithm which does not exhibit backtracking problems. If and
     39when that happens, it will likely be a sweeping change, and those
     40improvements will **not** be backported to legacy versions.
     41
     42In the near term, it is not reasonable to continue to play
     43whack-a-mole with security advisories, and so any future ReDoS
     44reports will be considered "working as intended", and resolved
     45entirely by this warning.
    946
    1047## Usage
    … …  
    397434Defaults to the value of `process.platform`.
    398435
     436### maxGlobstarRecursion
     437
     438Max number of non-adjacent `**` patterns to recursively walk
     439down.
     440
     441The default of `200` is almost certainly high enough for most
     442purposes, and can handle absurdly excessive patterns.
     443
     444If the limit is exceeded (which would require very excessively
     445long patterns and paths containing lots of `**` patterns!), then
     446it is treated as non-matching, even if the path would normally
     447match the pattern provided.
     448
     449That is, this is an intentional false negative, deemed an
     450acceptable break in correctness for security and performance.
     451
     452### maxExtglobRecursion
     453
     454Max depth to traverse for nested extglobs like `*(a|b|c)`
     455
     456Default is 2, which is quite low, but any higher value swiftly
     457results in punishing performance impacts. Note that this is _not_
     458relevant when the globstar types can be safely coalesced into a
     459single set.
     460
     461For example, `*(a|@(b|c)|d)` would be flattened into
     462`*(a|b|c|d)`. Thus, many common extglobs will retain good
     463performance and never hit this limit, even if they are
     464excessively deep and complicated.
     465
     466If the limit is hit, then the extglob characters are simply not
     467parsed, and the pattern effectively switches into `noextglob:
     468true` mode for the contents of that nested sub-pattern. This will
     469typically _not_ result in a match, but is considered a valid
     470trade-off for security and performance.
     471
    399472## Comparisons to other fnmatch/glob implementations
    400473
Note: See TracChangeset for help on using the changeset viewer.