Skip to content

fix(rules): rule precision — WH006/WH013, harvested-registry, npx text, proof suites - #879

Merged
hyperpolymath merged 7 commits into
fix/issue-sweepfrom
fix/rule-precision
Sep 30, 2026
Merged

hyperpolymath merged 7 commits into
fix/issue-sweepfrom
fix/rule-precision

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Stacked on #875 (base fix/issue-sweep; GitHub retargets to main when #875 merges). Merge #875 first.

What

  • WH006 skips reusable-workflow caller jobs (job-level uses:), where GitHub rejects timeout-minutes:. Refs standards#943.
  • extract_job_blocks: the last job of every workflow was never checked (in-flight job not flushed), and later jobs reported the first job's line number. Both fixed. Expect WH006 to find a few more true positives estate-wide.
  • WH013/WH002: git push <named non-origin remote> (gitlab/codeberg/backup mirrors) authenticates with its own key/token, so it doesn't need contents: write. Bare, origin and "$VAR" pushes still count. Refs standards#943.
  • ScannerSuppression: harvested-registry/ is exempt for secret_detected only. Closes secret_detected flags harvested reference material: path-based carve-out needed for harvested-registry/ (from #746 sample) #865.
  • npx_in_workflow message now recommends bunx/bun run (Deno banned 2026-09-22). Refs standards#938.
  • honest_completion no_tests: a proof suite whose checker runs in CI counts as tests. Refs echo-types#271.

Verification (local)

  • mix test: 1682 tests, 0 failures (242 excluded)
  • mix compile --warnings-as-errors --force: clean
  • Every change has fires / does-not-fire tests.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65

…xt, proof suites

- WH006: skip reusable-workflow caller jobs (job-level `uses:`) — GitHub
  rejects `timeout-minutes:` there (standards#943).
- extract_job_blocks: flush the final job (the last job of every workflow
  was never checked — silent false negative) and report each job's own
  line number instead of the first job's.
- WH013/WH002: `git push <named non-origin remote>` is a mirror push that
  authenticates with its own key/token and does not consume
  `contents: write`; strip it before judging writes (standards#943).
  Bare, `origin` and `"$VAR"` pushes still count.
- ScannerSuppression: `harvested-registry/` exempt for secret_detected
  only — third-party reference manifests (#865).
- npx_in_workflow: recommend `bunx`/`bun run`; Deno is banned since
  2026-09-22 (standards#938, LANGUAGE-POLICY §1.3).
- honest_completion no_tests: a proof suite whose checker runs in CI
  (agda/lake/lean/coqc/dune/idris2) counts as tests (echo-types#271).

Each change carries fires/does-not-fire regression tests.
mix test: 1682 tests, 0 failures (242 excluded); strict compile clean.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c1c779f8-76e3-44a4-9723-5bdfd14291d0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gitguardian

gitguardian Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 4 secrets following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secrets in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
37657201 Triggered Generic High Entropy Secret b7a0e10 test/scanner_suppression_test.exs View secret
37657201 Triggered Generic High Entropy Secret c892b80 test/scanner_suppression_test.exs View secret
37657201 Triggered Generic High Entropy Secret 065447f test/scanner_suppression_test.exs View secret
37657201 Triggered Generic High Entropy Secret 8105f56 test/scanner_suppression_test.exs View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

hyperpolymath and others added 5 commits September 30, 2026 10:59
… a src/

A root-relative `src/<dir>/` can only be rename drift of the repo root's
`src/` or the referencing doc's own directory's `src/`. In a repo with
neither — standards, whose specs and audits quote other repos' layouts —
the reference describes a foreign tree. Measured on standards main
(bd9313a6): 35 SD022 findings (34 baselined as cross-repo FPs + the k9
spec `src/tea/` in standards#945) → 1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
This reverts commit 9167ac7.

CodeRabbit's CI-fix agent rolled back the claimed_version/relabel fixes
and the `mix format` output to chase checks that fail for unrelated,
already-documented reasons (reusable workflows build hypatia HEAD, i.e.
broken main, until this PR merges). The rollback reintroduces the
Regex.run trailing-group bug and the `##`/lost-first-byte relabel bugs
that the tests in this PR pin down.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant