fix(rules): rule precision — WH006/WH013, harvested-registry, npx text, proof suites - #879
Conversation
…xt, proof suites - WH006: skip reusable-workflow caller jobs (job-level `uses:`) — GitHub rejects `timeout-minutes:` there (standards#943). - extract_job_blocks: flush the final job (the last job of every workflow was never checked — silent false negative) and report each job's own line number instead of the first job's. - WH013/WH002: `git push <named non-origin remote>` is a mirror push that authenticates with its own key/token and does not consume `contents: write`; strip it before judging writes (standards#943). Bare, `origin` and `"$VAR"` pushes still count. - ScannerSuppression: `harvested-registry/` exempt for secret_detected only — third-party reference manifests (#865). - npx_in_workflow: recommend `bunx`/`bun run`; Deno is banned since 2026-09-22 (standards#938, LANGUAGE-POLICY §1.3). - honest_completion no_tests: a proof suite whose checker runs in CI (agda/lake/lean/coqc/dune/idris2) counts as tests (echo-types#271). Each change carries fires/does-not-fire regression tests. mix test: 1682 tests, 0 failures (242 excluded); strict compile clean. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| 37657201 | Triggered | Generic High Entropy Secret | b7a0e10 | test/scanner_suppression_test.exs | View secret |
| 37657201 | Triggered | Generic High Entropy Secret | c892b80 | test/scanner_suppression_test.exs | View secret |
| 37657201 | Triggered | Generic High Entropy Secret | 065447f | test/scanner_suppression_test.exs | View secret |
| 37657201 | Triggered | Generic High Entropy Secret | 8105f56 | test/scanner_suppression_test.exs | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secrets safely. Learn here the best practices.
- Revoke and rotate these secrets.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
… a src/ A root-relative `src/<dir>/` can only be rename drift of the repo root's `src/` or the referencing doc's own directory's `src/`. In a repo with neither — standards, whose specs and audits quote other repos' layouts — the reference describes a foreign tree. Measured on standards main (bd9313a6): 35 SD022 findings (34 baselined as cross-repo FPs + the k9 spec `src/tea/` in standards#945) → 1. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
This reverts commit 9167ac7. CodeRabbit's CI-fix agent rolled back the claimed_version/relabel fixes and the `mix format` output to chase checks that fail for unrelated, already-documented reasons (reusable workflows build hypatia HEAD, i.e. broken main, until this PR merges). The rollback reintroduces the Regex.run trailing-group bug and the `##`/lost-first-byte relabel bugs that the tests in this PR pin down. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Stacked on #875 (base
fix/issue-sweep; GitHub retargets tomainwhen #875 merges). Merge #875 first.What
uses:), where GitHub rejectstimeout-minutes:. Refs standards#943.extract_job_blocks: the last job of every workflow was never checked (in-flight job not flushed), and later jobs reported the first job's line number. Both fixed. Expect WH006 to find a few more true positives estate-wide.git push <named non-origin remote>(gitlab/codeberg/backup mirrors) authenticates with its own key/token, so it doesn't needcontents: write. Bare,originand"$VAR"pushes still count. Refs standards#943.harvested-registry/is exempt forsecret_detectedonly. Closes secret_detected flags harvested reference material: path-based carve-out needed for harvested-registry/ (from #746 sample) #865.bunx/bun run(Deno banned 2026-09-22). Refs standards#938.no_tests: a proof suite whose checker runs in CI counts as tests. Refs echo-types#271.Verification (local)
mix test: 1682 tests, 0 failures (242 excluded)mix compile --warnings-as-errors --force: clean🤖 Generated with Claude Code
https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65