Finding
.githooks/validate-spdx.sh:47 iterates unquoted:
for file in $FILES_TO_CHECK
Unquoted word-splitting on a path list. The estate contains a directory with a
literal space in its name — _RSR _SET — so any path under it splits into two
bogus paths, and the validator checks files that do not exist while silently skipping
the one that does. A file-existence check on a split fragment fails open or errors,
neither of which is "this file lacks an SPDX header".
Source: developer/.claude/checkpoints/2026-09-22-cicd-pipeline-delivery.md §5-5.
Acceptance criteria
Decision sheet: #787
Finding
.githooks/validate-spdx.sh:47iterates unquoted:Unquoted word-splitting on a path list. The estate contains a directory with a
literal space in its name —
_RSR _SET— so any path under it splits into twobogus paths, and the validator checks files that do not exist while silently skipping
the one that does. A file-existence check on a split fragment fails open or errors,
neither of which is "this file lacks an SPDX header".
Source:
developer/.claude/checkpoints/2026-09-22-cicd-pipeline-delivery.md§5-5.Acceptance criteria
while IFS= read -r -d ''),not an unquoted word-split
space must be reported, and is missed before the fix
one instance suggests others
bash scripts/tests/validate-spdx-test.shgreenDecision sheet: #787