spotless icon indicating copy to clipboard operation
spotless copied to clipboard

Add a generic check against "dangerous" Unicode codepoints

Open TobiX opened this issue 4 years ago • 0 comments

It would be nice if spotless could check for (and remove or error out) "dangerous" unicode codepoints.

See today's Rust security advisory: https://blog.rust-lang.org/2021/11/01/cve-2021-42574.html - According to this, the initial list of forbidden codepoints should contain: U+202A, U+202B, U+202C, U+202D, U+202E, U+2066, U+2067, U+2068, U+2069

Additionally, it would be nice to have a similar check against homoglyph attacks, but that is probably a bit more tricky to solve...

TobiX avatar Nov 02 '21 00:11 TobiX