Repository navigation
fix: mask generic secrets and cloud account ids in scan reports - #11
Merged
Merged
Conversation
Adds a report pass, redact-secrets, between the path and identifier passes. It masks the value after a name ending in _KEY or -key, an Authorization header carrying a raw, Basic or Token credential, and any run of 32 or more base62/base64url characters that looks random, as [REDACTED:secret:generic]. The fallback also applies after a single "=" (VAR=value, --flag=value) and skips UUIDs, hex digests, integrity values, data URIs, runs ending in base64 padding, labels joined to a hash, runs of eight or more digits, and runs made mostly of ordinary words (kebab-case, snake_case, camelCase and PascalCase identifiers, short-segment deployment names such as pods and releases that hold three or more deployment words). It needs a digit, a letter and at least 4.0 bits of entropy per character. The identifier pass now redacts cloud account identifiers: any *ACCOUNT_ID, CF_ACCOUNT, CLOUDFLARE_ACCOUNT and project variable, account_id, --account-id/--account/--owner-id values shaped like an account, the account field of an arn:, a bare 32-hex operand of wrangler, and --project for gcloud, gsutil, bq and firebase. ssh -o User= (quoted or glued) redacts the login, and a flag ending in -key takes its value as a secret. Matching stays linear: tests time every pass of the report composition on 200,000-character repeats of underscores, quotes, digits, account names and similar shapes. Branch and folder names stay readable; tests pin that. The report copy and README describe the new passes and state that masking is best effort. Adds the new spelling words to the package word list. Regenerates plugin/scripts/guard-scan.mjs. Co-Authored-By: Claude <noreply@anthropic.com>
Adds a short section after the action table: what the guardrails address in the OWASP Top 10 lists and where the pack-to-risk table is, that a warn guardrail lets the action run and only ask and block stop it, and the risks Guard does not address because it sees commands and file paths, not prompts or file contents. Co-Authored-By: Claude <noreply@anthropic.com>
This reverts commit f311cca.
samc621
approved these changes
Oct 7, 2026
|
🎉 This PR is included in version 0.4.2 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Masks keys from unlisted providers, cloud account ids and ssh -o User logins in the scan report, and documents what the report still leaves readable.