java-topology/defects/sequelize/patch/sequelize-0002-expand-include-all-set.patch
russell@unturf.com d4ed2dff91 ORM wave: 24 defects patched across 10 ORMs (157 sites, 62 ecosystems)
Hibernate (5 HIGH): addColumn/addReferencedColumn/addIndex ArrayList→LinkedHashSet (19x)
  FK second-pass LinkedHashSet, orderHierarchy LinkedHashSet
MyBatis (1 MEDIUM): sortConstructorMappings indexOf→HashMap (12x)
EF Core (2 HIGH + 1 MEDIUM): FindGenerationProperty HashSet (250x),
  AddPrincipals HashSet (250x), FK discovery HashSet (6x)
Diesel (3 MEDIUM): SQLite/MySQL row position()→BTreeMap (51x)
SQLAlchemy (2 HIGH): _values_bindparam Set (500x), evaluated_keys Set (500x)
Peewee (1 MEDIUM): _SortedFieldList.index() bisect (42x)
Sequelize (2 HIGH): bulkInsert Set (50x), expandIncludeAll Set (250x)
TypeORM (3 HIGH): OrmUtils.uniq Map (500x), diffColumns Set (125x),
  updatedColumns Set (100x)
Doctrine ORM (1 HIGH + 2 MEDIUM): hydrator discriminator (26x),
  addSubClass (250x), SqlWalker partial (130x)
GORM (1 MEDIUM): sortCallbacks getRIndex→map (194x)
SQLite: SqliteTest unit proof 4/4 PASS (101x)

Unit tests: all PASS — Hibernate/MyBatis/EfCore/Diesel/SQLAlchemy/Peewee/
  Sequelize/TypeORM/Doctrine/GORM
Whitepaper: 157 sites, 62 ecosystems; PDF 752K
2026-03-27 13:34:26 -04:00

19 lines
758 B
Diff

diff --git a/packages/core/src/model.js b/packages/core/src/model.js
--- a/packages/core/src/model.js
+++ b/packages/core/src/model.js
@@ -515,9 +515,11 @@ class Model {
if (types !== true) {
// replace type placeholder e.g. 'One' with its constituent types
- // CWE-407: all.includes(type_) is O(|all|) inside a for loop = O(n^2)
all.splice(i, 1);
i--;
+ // CWE-407 fix: convert 'all' to a Set for O(1) membership check
+ const allSet = new Set(all);
for (const type_ of types) {
- if (!all.includes(type_)) {
+ if (!allSet.has(type_)) {
all.unshift(type_);
+ allSet.add(type_);
i++;
}
}