Skip to content

fix: decode URL-encoded characters in asset filenames - #569

Open
matthyx wants to merge 1 commit into
helm:mainfrom
matthyx:fix/url-decode-asset-filenames
Open

matthyx wants to merge 1 commit into
helm:mainfrom
matthyx:fix/url-decode-asset-filenames

Conversation

@matthyx

@matthyx matthyx commented Nov 21, 2025 •

Copy link
Copy Markdown

Chart packages with SemVer build metadata fail during indexing when GitHub encodes + as %2B in the asset URL: chart-releaser looks for test-chart-0.1.0%2Bbuild.1.tgz instead of the local test-chart-0.1.0+build.1.tgz.

Decode the asset filename in addToIndexFile() before accessing the local chart package. UpdateIndexFile() already reads the decoded url.URL.Path, so it requires no additional unescaping. The regression test verifies that the encoded asset URL resolves correctly and the index preserves version 0.1.0+build.1; its fake embeds the existing GitHub fake to support the current interface.

Closes #281.

Validation:

  • Regression test fails against upstream code with the expected file-not-found error and passes with the fix.
  • GIT_CONFIG_GLOBAL=/dev/null GIT_CONFIG_NOSYSTEM=1 go test ./... -race -count=1 passes. Git configuration is isolated because a local HTTPS-to-SSH rewrite breaks the existing TestGit_GetPushURL test.
  • go vet ./..., golangci-lint run --timeout 5m, formatting checks, and git diff --check pass.

@matthyx
matthyx force-pushed the fix/url-decode-asset-filenames branch from 1c72bf2 to b0c0bf7 Compare November 21, 2025 13:09
@matthyx

matthyx commented Dec 12, 2025

Copy link
Copy Markdown
Author

@cpanato can you have a look please?

Fixes helm#281

Decode the asset filename in addToIndexFile before accessing the local
chart package so SemVer build metadata encoded as %2B resolves to +.
UpdateIndexFile already uses the decoded URL.Path and needs no extra
unescaping.

Add a regression test for an encoded plus sign and verify that the index
preserves the chart version's build metadata.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>
@matthyx
matthyx force-pushed the fix/url-decode-asset-filenames branch from b0c0bf7 to eb67bdf Compare September 11, 2026 14:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

cr crashes as package version gets accidentially encoded

1 participant