Skip to content

Avoid sensitive pattern metadata in corpus reports - #14

Open
enoreyes wants to merge 1 commit into
mainfrom
feature/remote-workflows-protection
Open

Avoid sensitive pattern metadata in corpus reports#14
enoreyes wants to merge 1 commit into
mainfrom
feature/remote-workflows-protection

Conversation

@enoreyes

@enoreyes enoreyes commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

Problem

CodeQL identified a high-severity clear-text logging path from secret-pattern metadata into corpus verifier JSON output.

Scope

Change only the secret-finding diagnostic message and its regression test.

Non-goals

Do not weaken corpus scanning, change fixture acceptance, or dismiss the CodeQL alert.

Acceptance

All protected checks pass, fixture secret detection remains fail-closed, and a new main CodeQL analysis closes alert 1 without dismissal.

Validation

make lint && make typecheck && make test-gate && make build && make agent-ready && make verify-publication

Dependencies

No new runtime or CI dependencies.

Risk

Low. Finding categories are withheld from output; finding codes, paths, counts, and remediation remain available.

Rollout

Merge only after all protected checks pass, then verify a new main CodeQL analysis closes alert 1.

Observability

GitHub CodeQL alert 1 and the protected Quality/Security checks provide recovery evidence.

Documentation

No public documentation change is required because the corpus verifier contract is unchanged.

Compatibility

Machine-readable finding codes and schema remain compatible; only the human-readable message is safer.

Generated artifacts

No generated artifacts change.

Agent authorship

Authored by Factory Droid under the assigned remote-workflows protection feature.

Keep fail-closed corpus detection while withholding the matched category
from machine-readable output so diagnostics cannot become a sensitive-data
logging path.

Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
Signed-off-by: enoreyes <enoreyes@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant