Issue 457 sonarqube - #476
Merged
Merged
Conversation
… and addresses a potential Denial of Service as a result of polynomial runtime due to backtracking. This newer regular expression also finds matches in fewer steps.
…he expected results
…issue_457_sonarqube
22 tasks
mollybsmith-noaa
approved these changes
Jul 29, 2026
mollybsmith-noaa
left a comment
Collaborator
There was a problem hiding this comment.
Looks good to me!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request Testing
Describe testing already performed for these changes:
Generated tests to verify that new regex no longer raises SonarQube DOS (Denial of Service) warning due to polynomial runtime due to backtracking
Recommend testing for the reviewer(s) to perform, including the location of input datasets, and any additional instructions:
verify all tests are passing
Do these changes include sufficient documentation updates, ensuring that no errors or warnings exist in the build of the documentation? [NAo]
Do these changes include sufficient testing updates? [Yes]
Will this PR result in changes to the test suite? [No]
If yes, describe the new output and/or changes to the existing output:
Do these changes introduce new SonarQube findings? [No]
If yes, please describe:
Please complete this pull request review by [Before August 4].
Pull Request Checklist
See the METplus Workflow for details.
Select: Reviewer(s) and Development issue
Select: Milestone as the version that will include these changes
Select: Coordinated METplus-X.Y Support project for bugfix releases or METcalcpy-X.Y.Z Development project for official releases