Repository navigation
fix(preview): fence version cells so a backtick cannot break the PR comment table - #1260
Merged
Merged
Conversation
BryanFRD
enabled auto-merge (squash)
October 3, 2026 10:28
Contributor
There was a problem hiding this comment.
Nothing blocking. code_cell follows CommonMark code span rules. The fence is one backtick longer than the longest run inside, so the span can't close early. The padding is only added when the value starts or ends with a backtick, and the renderer strips exactly that one space. Leaving HTML entities unescaped is correct here, because inside a code span they would show up literally. \| is the GFM-sanctioned way to keep a pipe inside a code span in a table cell. The tests cover the cases that matter, including the empty value.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1234
The version columns of the preview comment were wrapped in a single-backtick code span and passed through
escape_md_cell, which escapes with backslashes. Markdown ignores backslash escapes inside a code span, so a backtick in a version still closed the span, and\or<showed up literally.Version cells now go through
code_cell: the fence is one backtick longer than the longest run in the value, padded with a space when the value starts or ends with a backtick, as CommonMark specifies. Inside the span only|is escaped (GFM splits table cells before inline parsing) and newlines become spaces. Everything else stays literal, which is safe because a code span renders nothing as HTML. Name and bump cells keepescape_md_cell.The existing hostile-input test asserted the broken output; it now expects the fenced form.