Skip to content

fix(security): preserve exact finding identity - #409

Draft
Spectorian wants to merge 3 commits into
mainfrom
codex/security-finding-integrity
Draft

fix(security): preserve exact finding identity#409
Spectorian wants to merge 3 commits into
mainfrom
codex/security-finding-integrity

Conversation

@Spectorian

@Spectorian Spectorian commented Aug 21, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • derive finding identity from complete analyzer matches before retaining bounded display previews
  • select deterministic severity-first representatives while preserving distinct occurrences and source scope
  • keep full match content ephemeral across static, YARA, MCP tool-poisoning, and rug-pull findings
  • bound public context and evidence surfaces, and report partial analysis when YARA fingerprint work reaches its limit

Validation

  • long-prefix collision, exact-duplicate, severity, source-binding, occurrence, and idempotence regressions
  • terminal, JSON, Markdown, SARIF, Python, and MCP serialization checks
  • branch-wide non-integration/non-provider suite
  • Ruff lint, format, targeted mypy, and git diff --check

Signed-off-by: Nir Paz <npaz@nvidia.com>
Signed-off-by: Nir Paz <npaz@nvidia.com>
Signed-off-by: Nir Paz <npaz@nvidia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant