Skip to content

fix(shared): use slice(-2) for UEN T-series 2-digit year so future years reject - #10026

Merged
kevin9foong merged 3 commits into
opengovsg:developfrom
soroush5:fix/uen-future-year-substring
Sep 29, 2026
Merged

kevin9foong merged 3 commits into
opengovsg:developfrom
soroush5:fix/uen-future-year-substring

Conversation

@soroush5

Copy link
Copy Markdown

substring(-2) returns the whole year string, so the future-year guard never fired. One-line fix to slice(-2). Verified: fake T99 rejected after, valid T09 still passes.

Fixes #10025

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Add a regression test covering a valid-checksum future T-series value.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Fixes future-year validation for T-series UENs by correctly extracting the final two year digits.

Changes:

  • Replaces substring(-2) with slice(-2).
File summaries
File Summary
packages/shared/utils/uen-validation.ts Corrects T-series future-year validation.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.


const currentYear = parseInt(
new Date().getFullYear().toString().substring(-2),
new Date().getFullYear().toString().slice(-2),
@endor-labs-pro

endor-labs-pro Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Warning

Endor Labs detected 1 policy violations associated with this pull request.

Please review the findings that caused the policy violations.

📋 Policy: PR Warn (22 findings)

📥 Package npm://[email protected]

⤵️ Dependency: npm://[email protected]
🚩 GHSA-qfvm-cv95-jqjf: multer vulnerable to Denial of Service via file descriptor leak on aborted uploads

Details

  • Severity: High
  • Tags: Direct Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Update [email protected] to use multer version 2.3.0 (current: 2.2.0, latest: 3.0.0-alpha.2).
🚩 GHSA-535w-7cp7-47q4: multer vulnerable to Denial of Service via oversized array index in field names

Details

  • Severity: High
  • Tags: Direct Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Update [email protected] to use multer version 2.3.0 (current: 2.2.0, latest: 3.0.0-alpha.2).
🚩 GHSA-wc9g-mqfw-jrwm: multer vulnerable to Denial of Service via crafted multipart field names

Details

  • Severity: High
  • Tags: Direct Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Update [email protected] to use multer version 2.3.0 (current: 2.2.0, latest: 3.0.0-alpha.2).
⤵️ Dependency: npm://[email protected]
🚩 GHSA-p9j2-gv94-2wf4: Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

Details

🚩 GHSA-89xv-2m56-2m9x: Next.js: Server-Side Request Forgery in Server Actions on custom servers

Details

🚩 GHSA-2xp9-vwfh-vxw4: Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

Details

🚩 GHSA-m99w-x7hq-7vfj: Next.js: Denial of Service in App Router using Server Actions

Details

⤵️ Dependency: npm://[email protected]
🚩 GHSA-cc9r-2j5m-2m83: Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain

Details

  • Severity: Medium
  • Tags: Direct Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Upgrade nodemailer to version 9.1.0 (current: 9.0.1, latest: 10.0.10).
🚩 GHSA-wmmp-3585-3rmp: Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

Details

  • Severity: Medium
  • Tags: Direct Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Upgrade nodemailer to version 9.1.0 (current: 9.0.1, latest: 10.0.10).
🚩 GHSA-8m3c-c648-2xjj: Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature

Details

  • Severity: Medium
  • Tags: Direct Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Upgrade nodemailer to version 9.1.1 (current: 9.0.1, latest: 10.0.10).
🚩 GHSA-2x7j-588g-ccc2: Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list

Details

  • Severity: High
  • Tags: Direct Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Upgrade nodemailer to version 9.1.0 (current: 9.0.1, latest: 10.0.10).
⤵️ Dependency: npm://[email protected]
🚩 GHSA-4mjr-xmp4-gh2g: qs: Denial of Service via Attacker Controlled isBuffer

Details

  • Severity: Medium
  • Tags: Transitive Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Upgrade qs to version 6.16.0 (current: 6.15.1, latest: 6.16.0).
🚩 GHSA-q8mj-m7cp-5q26: qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set

Details

  • Severity: Medium
  • Tags: Transitive Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Upgrade qs to version 6.15.2 (current: 6.15.1, latest: 6.16.0).

📥 Package npm://[email protected]

⤵️ Dependency: npm://[email protected]
🚩 GHSA-55q2-fjhq-7xh7: DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

Details

  • Severity: Medium
  • Tags: Transitive Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Upgrade dompurify to version 3.4.13 (current: 3.4.12, latest: 3.4.15).
⤵️ Dependency: npm://[email protected]
🚩 GHSA-q8mj-m7cp-5q26: qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set

Details

  • Severity: Medium
  • Tags: Transitive Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Upgrade qs to version 6.15.2 (current: 6.15.1, latest: 6.16.0).
🚩 GHSA-4mjr-xmp4-gh2g: qs: Denial of Service via Attacker Controlled isBuffer

Details

  • Severity: Medium
  • Tags: Transitive Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Upgrade qs to version 6.16.0 (current: 6.15.1, latest: 6.16.0).
⤵️ Dependency: npm://[email protected]
🚩 GHSA-337j-9hxr-rhxg: React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration

Details

  • Severity: Medium
  • Tags: Direct Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Update [email protected] to use react-router-dom version 7.0.0-pre.0 (current: 6.30.4, latest: 7.18.4).
🚩 GHSA-wrjc-x8rr-h8h6: React Router: Open redirect via backslash in and useNavigate (CVE-2025-68470 bypass)

Details

  • Severity: Medium
  • Tags: Direct Normal Reachable Dependency Reachable Function Fix Available Warning
  • Categories: SCA Vulnerability Security
  • Remediation: Update [email protected] to use react-router-dom version 7.0.0-pre.0 (current: 6.30.4, latest: 7.18.4).

📥 Package npm://[email protected]

⤵️ Dependency: npm://[email protected]
🚩 GHSA-p9j2-gv94-2wf4: Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

Details

🚩 GHSA-m99w-x7hq-7vfj: Next.js: Denial of Service in App Router using Server Actions

Details

🚩 GHSA-2xp9-vwfh-vxw4: Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

Details

🚩 GHSA-89xv-2m56-2m9x: Next.js: Server-Side Request Forgery in Server Actions on custom servers

Details


This comment was automatically generated by Endor Labs.
Scanned @ 09-18-2026 04:49:42 UTC

})

it('should reject a future T-series year with a valid checksum', () => {
// T99SS0032K has a valid checksum (via calcOtherCheckDigit) but year 99

@kevin9foong kevin9foong Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hey @soroush5, thanks for the contribution.

LGTM 👍 , but shall we update to remove the context about the previous substring(-2) as might not be useful in the long run?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, trimmed it down to just what the test checks.

@soroush5

Copy link
Copy Markdown
Author

Hi, gentle nudge on the UEN year fix. Can add more T-series cases if useful.

@kevin9foong

Copy link
Copy Markdown
Contributor

LGTM 👍

@mergify

mergify Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again.

@kevin9foong
kevin9foong merged commit 772739b into opengovsg:develop Sep 29, 2026
3 checks passed
kevin9foong added a commit that referenced this pull request Sep 29, 2026
#10026 left the currentYear parseInt call split across lines, which
fails the prettier/prettier lint rule in CI.

Co-authored-by: Claude Opus 5.5 (1M context) <[email protected]>
@soroush5

Copy link
Copy Markdown
Author

Thanks for the review and the merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

UEN T-series future-year check never rejects (substring with negative index)

3 participants