Avoid sensitive pattern metadata in corpus reports - #14
Open
enoreyes wants to merge 1 commit into
Open
Conversation
Keep fail-closed corpus detection while withholding the matched category from machine-readable output so diagnostics cannot become a sensitive-data logging path. Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com> Signed-off-by: enoreyes <enoreyes@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
CodeQL identified a high-severity clear-text logging path from secret-pattern metadata into corpus verifier JSON output.
Scope
Change only the secret-finding diagnostic message and its regression test.
Non-goals
Do not weaken corpus scanning, change fixture acceptance, or dismiss the CodeQL alert.
Acceptance
All protected checks pass, fixture secret detection remains fail-closed, and a new main CodeQL analysis closes alert 1 without dismissal.
Validation
make lint && make typecheck && make test-gate && make build && make agent-ready && make verify-publicationDependencies
No new runtime or CI dependencies.
Risk
Low. Finding categories are withheld from output; finding codes, paths, counts, and remediation remain available.
Rollout
Merge only after all protected checks pass, then verify a new main CodeQL analysis closes alert 1.
Observability
GitHub CodeQL alert 1 and the protected Quality/Security checks provide recovery evidence.
Documentation
No public documentation change is required because the corpus verifier contract is unchanged.
Compatibility
Machine-readable finding codes and schema remain compatible; only the human-readable message is safer.
Generated artifacts
No generated artifacts change.
Agent authorship
Authored by Factory Droid under the assigned remote-workflows protection feature.