fix(env): 템플릿 secret 판정 정밀화#109
Merged
Merged
Conversation
env template secret warning을 key-aware classifier로 전환하고 Rust/JS fallback 동작을 맞춘다. Closes #107
Owner
Author
|
독립 fresh-session 리뷰 결과
Note: GitHub 정책상 self-authored PR에는 공식 approve review를 제출할 수 없어 동일한 독립 리뷰 verdict를 PR comment로 남깁니다. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
배경
.env.example/.env.local.example같은 env contract 파일에서 긴 문자열이라는 이유만으로 public/config 값이env-example-secretwarning에 섞이던 노이즈를 줄입니다.변경 사항
env-example-secretfinding 생성부가 key와 value를 함께 보도록 바꿨습니다.검증
cargo test -p maximus-core --test core_modelscargo test -p maximus-checks --test env_checksnpm test -- test/env-fix.test.jsgit diff --checkauditProjectenv-example-secret check via temp projectgit diff --name-only origin/master가 issue [Maximus] Env template secret heuristic을 key-aware로 정밀화 #107 allowlist 6개 파일 안에 머무는지 확인브랜치 / 워크트리
mastercodex/fix-107-key-aware-env-secrets/private/tmp/maximus-audit-signal-wave1-20260505/issue-107-key-aware-env-secrets10429cd fix(env): 템플릿 secret 판정 정밀화이슈 연결
Closes #107