Merge branch 'master' into issue-1405

This commit is contained in:
Timofey Kachalov
2026-07-10 20:13:52 +04:00
committed by GitHub
4 changed files with 109 additions and 2 deletions
+2 -1
View File
@@ -2,8 +2,9 @@ Change Log
v5.4.7
---
* Bumped the production `brace-expansion` transitive dependency to a patched version, resolving `CVE-2026-25547`. Fixes https://github.com/javascript-obfuscator/javascript-obfuscator/issues/1405
* Fixed `sourceMapFileName` ending in `.js.map` (e.g. `foo.min.js.map`) being mangled in the emitted `//# sourceMappingURL=` comment. Fixes https://github.com/javascript-obfuscator/javascript-obfuscator/issues/1312
* Fixed `URIError: URI malformed` crash when `stringArray` with `base64`/`rc4` encoding processed a string literal containing lone surrogate code units (e.g. `"[^\uD800-\uDFFF]"`). Fixes https://github.com/javascript-obfuscator/javascript-obfuscator/issues/1431
* Bumped the production `brace-expansion` transitive dependency to a patched version, resolving `CVE-2026-25547`. Fixes https://github.com/javascript-obfuscator/javascript-obfuscator/issues/1405
v5.4.6
---
@@ -12,7 +12,19 @@ export const SourceMapFileNameRule: TOptionsNormalizerRule = (options: IOptions)
let { sourceMapFileName }: { sourceMapFileName: string } = options;
if (sourceMapFileName) {
sourceMapFileName = sourceMapFileName.replace(/^\/+/, '').replace(/(?:\.js)?(?:\.map)?$/, '');
sourceMapFileName = sourceMapFileName.replace(/^\/+/, '');
// a fully-qualified `*.js.map` file name is already in the canonical form, so it is kept as-is
// (otherwise the extension-stripping heuristic below would mangle names like `foo.min.js.map`)
// https://github.com/javascript-obfuscator/javascript-obfuscator/issues/1312
if (sourceMapFileName.endsWith('.js.map')) {
return {
...options,
sourceMapFileName
};
}
sourceMapFileName = sourceMapFileName.replace(/(?:\.js)?(?:\.map)?$/, '');
let sourceMapFileNameParts: string[] = sourceMapFileName.split(StringSeparator.Dot);
const sourceMapFileNamePartsCount: number = sourceMapFileNameParts.length;
@@ -0,0 +1,52 @@
import { assert } from 'chai';
import { NO_ADDITIONAL_NODES_PRESET } from '../../../src/options/presets/NoCustomNodes';
import { SourceMapMode } from '../../../src/enums/source-map/SourceMapMode';
import { JavaScriptObfuscator } from '../../../src/JavaScriptObfuscatorFacade';
//
// https://github.com/javascript-obfuscator/javascript-obfuscator/issues/1312
//
describe('Issue #1312', () => {
describe('`sourceMappingURL` should use the provided `sourceMapFileName`', () => {
describe('Variant #1: `*.min.js.map` file name', () => {
const sourceMappingUrlRegExp: RegExp = /\/\/# sourceMappingURL=a\.min\.js\.map$/;
let obfuscatedCode: string;
before(() => {
obfuscatedCode = JavaScriptObfuscator.obfuscate("console.log('Hello World');", {
...NO_ADDITIONAL_NODES_PRESET,
sourceMap: true,
sourceMapMode: SourceMapMode.Separate,
sourceMapFileName: 'a.min.js.map'
}).getObfuscatedCode();
});
it('should keep the full `.js.map` file name in the `sourceMappingURL`', () => {
assert.match(obfuscatedCode, sourceMappingUrlRegExp);
});
});
describe('Variant #2: base name without extension still gets `.js.map`', () => {
const sourceMappingUrlRegExp: RegExp = /\/\/# sourceMappingURL=a\.js\.map$/;
let obfuscatedCode: string;
before(() => {
obfuscatedCode = JavaScriptObfuscator.obfuscate("console.log('Hello World');", {
...NO_ADDITIONAL_NODES_PRESET,
sourceMap: true,
sourceMapMode: SourceMapMode.Separate,
sourceMapFileName: 'a'
}).getObfuscatedCode();
});
it('should append `.js.map` to a bare file name', () => {
assert.match(obfuscatedCode, sourceMappingUrlRegExp);
});
});
});
});
@@ -700,6 +700,48 @@ describe('OptionsNormalizer', () => {
assert.deepEqual(optionsPreset, expectedOptionsPreset);
});
});
// https://github.com/javascript-obfuscator/javascript-obfuscator/issues/1312
describe('Full `.js.map` file name is preserved as-is', () => {
before(() => {
optionsPreset = getNormalizedOptions({
...getDefaultOptions(),
sourceMapBaseUrl: 'http://localhost:9000',
sourceMapFileName: 'outputSourceMapName.min.js.map'
});
expectedOptionsPreset = {
...getDefaultOptions(),
sourceMapBaseUrl: 'http://localhost:9000/',
sourceMapFileName: 'outputSourceMapName.min.js.map'
};
});
it('should normalize options preset', () => {
assert.deepEqual(optionsPreset, expectedOptionsPreset);
});
});
// https://github.com/javascript-obfuscator/javascript-obfuscator/issues/1312
describe('Full `.js.map` file name with leading slashes', () => {
before(() => {
optionsPreset = getNormalizedOptions({
...getDefaultOptions(),
sourceMapBaseUrl: 'http://localhost:9000',
sourceMapFileName: '//outputSourceMapName.min.js.map'
});
expectedOptionsPreset = {
...getDefaultOptions(),
sourceMapBaseUrl: 'http://localhost:9000/',
sourceMapFileName: 'outputSourceMapName.min.js.map'
};
});
it('should normalize options preset', () => {
assert.deepEqual(optionsPreset, expectedOptionsPreset);
});
});
});
describe('splitStringsChunkLengthRule', () => {