Skip to content

fix(renavam): reject negative and fractional numbers - #592

Merged
hyanmandian merged 1 commit into
brazilian-utils:mainfrom
kwy404:fix/renavam-reject-signed-fractional-numbers
Sep 28, 2026
Merged

hyanmandian merged 1 commit into
brazilian-utils:mainfrom
kwy404:fix/renavam-reject-signed-fractional-numbers

Conversation

@kwy404

@kwy404 kwy404 commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

Root cause: isValidRenavam accepts a number, turns it into a string with toString() and then strips the mask characters with SEPARATORS_REGEX (whitespace, dot, hyphen). In a number, the minus sign and the decimal point are not a mask, but they are removed all the same, so a negative or fractional number is validated as the digits that are left:

isValidRenavam(-639884962); // true, read as 639884962
isValidRenavam(63988496.2); // true, read as 639884962

Fix: the first guard now uses isLookupCode, the helper added in 9cb73d0 ("reject negative, fractional and unsafe numbers in every code lookup") and already used by isValidCreditCard, isValidNcm, isValidCfop, isValidCst and isValidCsosn. A string is handled exactly as before; a number is only read as a RENAVAM when it is a non-negative safe integer. The JSDoc gets one sentence and one example saying so.

Test: a new case in is-valid-renavam.test.ts, "when it is a negative or fractional number", expects false for -639_884_962 and 63_988_496.2. It fails on main (expected true to be false) and passes with the fix.

Checklist

  • My commit/PR title follows Conventional Commits (e.g. feat: ..., fix: ..., docs: ...).
  • I added or updated tests covering this change (npm test).
  • I updated the documentation if this adds/changes a utility, in both: not needed, see below.
    • docs/utilities.md (English)
    • docs/pt-br/utilities.md (Portuguese)
  • npm run check passes locally (format, lint, types).
  • I ran npm run build:llms if I touched docs/utilities.md (the Check workflow fails when docs/llms.txt is stale): not touched.
  • This change does not introduce a breaking change, or I flagged it clearly below and it was discussed with maintainers beforehand.
  • This change does not add any runtime dependency (this library is zero-runtime-dependency by design).

Additional context

  • About "no narrower accepted input": every non-negative integer gets the same answer as before, because a RENAVAM has at most 11 digits and never comes near Number.MAX_SAFE_INTEGER (639_884_962 in the existing test still passes). Only negative and fractional numbers, which are never a RENAVAM, stop validating, the same change 9cb73d0 made for isValidCreditCard.
  • The examples in docs/utilities.md and docs/pt-br/utilities.md are all strings and behave the same, so the docs pages are unchanged.
  • Ran locally: vp check clean; vp test run --coverage with 6132 tests passing and 100% coverage; stryker run --mutate src/is-valid-renavam/is-valid-renavam.ts with 27 of 27 mutants killed (score 100); jscpd, knip and npm run check:api clean.

@kwy404
kwy404 requested a review from hyanmandian as a code owner September 26, 2026 04:29
@vercel

vercel Bot commented Sep 26, 2026

Copy link
Copy Markdown

@kwy404 is attempting to deploy a commit to the Hyan Mandian's projects Team on Vercel.

A member of the Team first needs to authorize it.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 80c1b65d-636e-4b83-a44f-ad33a5033867

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyanmandian

Copy link
Copy Markdown
Member

Awesome @kwy404! Thanks! I gonna add it as part of 2.5.0 release!

@pkg-pr-new

pkg-pr-new Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@brazilian-utils/brazilian-utils@592

commit: 93aca38

@codecov

codecov Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (cd0c587) to head (93aca38).

Additional details and impacted files
@@            Coverage Diff            @@
##              main      #592   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files          186       186           
  Lines         2069      2069           
  Branches       613       613           
=========================================
  Hits          2069      2069           
Flag Coverage Δ
node 100.00% <100.00%> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@hyanmandian

Copy link
Copy Markdown
Member

@claude could you please check if there's any other "isValid" utility that should use the isLookupCode? if so, create one PR stacked on top of this one fixing those too!

@hyanmandian

Copy link
Copy Markdown
Member

@kwy404 could you rebase? I fixed the build issue!

isValidRenavam turned a number into a string and then dropped the
separators, so the minus sign and the decimal point of a number were
read as mask characters and -639884962 and 63988496.2 both validated
as the RENAVAM 639884962. A number is now only read as a RENAVAM when
it is a non-negative safe integer, through the isLookupCode guard that
the code lookups and isValidCreditCard already use since 9cb73d0.
Strings keep their mask handling unchanged.

Signed-off-by: kwy404 <thekaway404@gmail.com>
@kwy404
kwy404 force-pushed the fix/renavam-reject-signed-fractional-numbers branch from 7fe2f8c to 93aca38 Compare September 26, 2026 18:28
@kwy404

kwy404 commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

Rebased on main, thanks! The RENAVAM tests pass locally (28 of 28).

@hyanmandian
hyanmandian merged commit 82d8395 into brazilian-utils:main Sep 28, 2026
25 of 26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants