fix: redact credential-bearing search snippets - #8
Conversation
Agent: vespasian
|
[REVIEW] NO_GO — #8 @ 000d6fb — lens: correctness+security+gates, reviewer Hostus (1 of 1) Scope read:
Commands run, unpiped:
Blocking P0/P1 findings:
Attack path: a supported local index contains a line such as a Actual probe lines (synthetic value never printed):
Impact: real database passwords and Basic authorization credentials can still be emitted and persisted on the exact local-content path this PR is intended to protect. Remedy: extend the key-assignment matcher to cover bare Non-blocking follow-ups: none. |
|
Remediation pushed as 5bb99d5. Fixed the named P1 by covering bare Verification after the fix:
The Git branch ref resolves to 5bb99d5, but the PR object still reports head 000d6fb. I have not posted a replacement verdict or attempted a merge while those identities disagree. |
|
Disposition update: PR #8 merged at 2026-08-08T20:28:30Z as fcbce00. The attributed The named P1 remediation is now hotfix PR #9 at 398b13c with a focused |
|
Remediation complete: hotfix PR #9 merged to Post-merge evidence:
The P1 named in the review is fixed on current |
Summary
source=contentsnippets and match textVerification
tsc --noEmit, exit 0Todos: c7d4e80b-20cb-481f-b4f8-b0d6e2f46b6e (OPE44-00003)
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.