Skip to content

Fix actionable Sonar findings - #2697

Open
msarahan wants to merge 1 commit into
NVIDIA:release/26.10from
msarahan:codex/sonar-open-findings
Open

msarahan wants to merge 1 commit into
NVIDIA:release/26.10from
msarahan:codex/sonar-open-findings

Conversation

@msarahan

@msarahan msarahan commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Why

Address the immediately actionable Sonar findings that improve security, reliability, and generated-document accessibility without changing dependency-resolution policy or performing broad algorithmic refactors.

https://sonar.nvidia.com/project/issues?issueStatuses=OPEN,CONFIRMED&id=RAPIDS_security_RAPIDS_cuvs

What changed

  • Remove shell-based execution from the clang compilation helper and add a regression test proving command arguments cannot trigger shell execution.

  • Correct Doxygen and Fern stylesheet defects identified as bugs.

  • Use Bash [[ ... ]] conditionals consistently in Bash-only scripts.

  • Normalize shell helper names and positional-argument handling.

  • Send error diagnostics to stderr and consolidate repeated shell expressions.

Remove unsafe shell-based command execution, preserve intended script behavior while resolving shell reliability findings, and correct the reported documentation and stylesheet defects. Add a regression test ensuring compiler commands are executed without a shell.

Created with Codex (GPT-5).
@msarahan
msarahan requested review from a team as code owners September 28, 2026 23:19
@msarahan
msarahan requested review from a team as code owners September 28, 2026 23:19
@msarahan msarahan added improvement Improves an existing functionality non-breaking Introduces a non-breaking change labels Sep 28, 2026

@imotov imotov left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems pretty reasonable and more idiomatic from the java/lucene side of things.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

improvement Improves an existing functionality non-breaking Introduces a non-breaking change

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

2 participants