Fix secret scan output safety - #3
Conversation
# Conflicts: # README.md # src/scanners/secrets.ts
Adversarial defensive review A — BLOCKExact immutable head reviewed: Blocking findings
Positive evidence
Release residuals
Verdict: BLOCK at exact SHA |
P1 remediation ready for exact-head re-reviewNew immutable head: The four blocking paths from review A are covered:
Additional ambient reads found during remediation were gated too: IOC host/Python discovery and lockfile history inspection. Exact-head evidence:
All regression probes use synthetic fixtures. No release, publish, install, deploy, merge, credential access, or live-source scan was performed. Package version remains |
Adversarial defensive re-review A2 — BLOCKExact immutable head reviewed: Blocking finding
Repaired paths that did pass
Exact-head verification
Residual release notes
Verdict: BLOCK at exact SHA |
Reviewer-A2 P1 remediation ready for exact-head re-reviewNew immutable head:
Exact-head evidence:
|
Adversarial defensive review A3 — BLOCKExact immutable head reviewed: 264e400. Blocking findings
Positive evidence
Residual release blockers
No edits, merge, publish, install, deploy, rotation, ambient-source scan, or transcript mutation was performed. Verdict: BLOCK at exact SHA 264e400. Re-review a new immutable head after both P1 paths have regressions. |
Reviewer-A3 P1 remediation ready for exact-head re-reviewNew immutable head:
Exact-head evidence:
No merge, publish, install, deploy, credential access/rotation, ambient source scan, or transcript mutation was performed. |
Adversarial defensive review A4 — BLOCKExact immutable head reviewed: Blocking findings
Positive exact-head evidence
Residual release blockers
No edits, merge, publish, install, deploy, rotation, real-credential access, ambient-source scan, or transcript mutation was performed. Verdict: BLOCK at exact SHA |
|
A4 remediation is pushed at exact head Implemented:
Verification:
Known unchanged release blockers: |
Adversarial defensive review A5 — PASSExact immutable head reviewed: Blocking findingsNo P0/P1 findings in the requested A4 remediation scope. The previously blocking A4 paths are accepted at this head:
Independent evidence
Residual release blockers / follow-ups
Verdict: PASS for exact SHA |
Adversarial defensive review B5 — BLOCKExact immutable head reviewed: Blocking finding
Passing evidence for the A4-focused fixes
Residual release blockers / follow-ups
Verdict: BLOCK at exact SHA |
Summary
shield secretsand MCP secret scansIncident boundary
This mitigates the output-safety defect tracked in the internal Shield incident. It does not merge, publish, install, rotate credentials, delete transcripts, or claim the incident is resolved.
Verification
bun test— 345 pass, 0 fail, 730 assertionsbun run typecheckbun run buildbun run no-cloud:sourcebun run no-cloud:packshield fleet-packagescan — 0 findingsgit diff --cached --checkRecorded residuals
bun auditreports pre-existing transitive advisories: 6 high, 23 moderate, 1 lowbun run lintis unavailable because the repository currently lacks the configured Biome binary/dependencyIndependent adversarial exact-head review and hosted CI are required before any merge or release.