From 80228e0a3b883ccdf2d80ba544c01619a856ef9c Mon Sep 17 00:00:00 2001 From: nsfisis Date: Mon, 20 Jul 2026 15:36:54 +0900 Subject: fix(advisory): treat int-keyed ignore entries as plain IDs parseIgnoreWithApply distinguishes ['CVE-123' => 'reason'] from [0 => 'CVE-123'] by checking is_int($key) in PHP. AuditConfig only matched on the value's type, so a canonical-int-keyed string value was mistaken for an id => reason pair. Expose canonical_int_key from the php-shim to replicate PHP's key-canonicalization rule and unignore test_mixed_formats. --- crates/shirabe-php-shim/src/var.rs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'crates/shirabe-php-shim/src') diff --git a/crates/shirabe-php-shim/src/var.rs b/crates/shirabe-php-shim/src/var.rs index f0e55d53..513c3e88 100644 --- a/crates/shirabe-php-shim/src/var.rs +++ b/crates/shirabe-php-shim/src/var.rs @@ -79,7 +79,7 @@ fn serialize_float(f: f64) -> String { /// Returns the integer a PHP array key string normalizes to, or None if the key stays a string. /// PHP treats a key as an integer only when it is a canonical decimal integer: no leading `+`, no /// redundant leading zeros, and within the platform integer range ("-0" is not canonical). -fn canonical_int_key(key: &str) -> Option { +pub fn canonical_int_key(key: &str) -> Option { if key == "0" { return Some(0); } -- cgit v1.3.1