Repository navigation
Conversation
…ame/value lists
The ECS environment idiom { name = "DB_PASSWORD", value = "hunter2" } names the
secret in the name literal, not in a key, so key-name redaction let the value
reach graph.json and the MCP surface verbatim. When a map's name literal
matches the sensitive pattern, redact its value/valueFrom.
Fixes Graphify-Labs#3787
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Thanks for the pull request, @breken-ai. A maintainer will review it soon. Want to talk it through while it is in review? Come join us on our Discord server. For longer-form discussion there is also GitHub Discussions. A couple of things that speed up review: make sure the test suite passes on Python 3.10 and 3.13, and that the change keeps extraction deterministic. |
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Redacts secrets in the name/value-pair idiom (ECS environment/secrets, any [{name, value}] list): when _redact_value sees a dict whose name literal matches the sensitive-key pattern, it now redacts the paired value/valueFrom/value_from entry, closing a leak where { name = "DB_PASSWORD", value = "hunter2" } reached graph.json verbatim. Non-secret pairs like { name = "LOG_LEVEL", value = "debug" } pass through untouched.
No blocking issues surfaced. 5 lower-confidence candidates did not survive cross-model review.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 1460 functions depend on the 54 functions this change touches.
Health — this change adds coupling hotspots:
- new:
extract()— 711 callers, 48 callees - new:
_rebuild_code()— 144 callers, 55 callees - new:
main()— 98 callers, 3 callees - new:
dispatch_command()— 2 callers, 125 callees - new:
extract_terraform()— 23 callers, 8 callees - new:
run_pipeline()— 8 callers, 13 callees - new:
watch()— 5 callers, 7 callees - new:
_build()— 7 callers, 3 callees - …and 10 more — each is listed as a finding
Verification — 1460 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 795 function(s) in the blast radius were not formally verified this run
Test selection
Test selection
2 of 302 test file(s) selected (1%) via static blast radius.
tests/test_terraform.py— impact, changed-testtests/test_terraform_modules.py— impact
Selection is safe under the controlled-regression assumption; always-run tests + a periodic full run are the backstops. Advisory — it never changes the check verdict.
· 18 more finding(s) on lines outside this diff (see the check run).
Security: close the Fortran cpp #include arbitrary-file-read (GHSA-pcc4-rvhr-2pr8), the last Aider/Devin monolith --watch shell sink (#3852), and terraform name/value secret redaction (#3870). Plus Windows watch rebuild locking (#3883), C# tuple element-name refs (#3877), JSX component-usage calls (#3855), and nested scan-root Python import projection (#3867). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Shipped in v0.9.70 (now on PyPI) via an authorship-preserving cherry-pick, so your commit keeps contributor-graph credit. Thanks @breken-ai! Redacts a value paired with a secret-named name in name/value pair lists. Release: https://github.com/Graphify-Labs/graphify/releases/tag/v0.9.70 |
What does this PR do?
Fixes #3787, a follow-up to #3817.
What: a Terraform
{ name = "DB_PASSWORD", value = "hunter2" }pair putshunter2in graph.json and the MCPquery/get_nodeoutput verbatim. That is the usual shape for ECS environment lists and for module inputs such asenvironment = [...].Why:
_redact_valuedecides by the map KEY. Here the keys are the genericnameandvalue, and the secret signal is thenameliteral, so nothing matched.Small example:
environment = [{ name = "DB_PASSWORD", value = "hunter2" }, { name = "LOG_LEVEL", value = "debug" }][{name: DB_PASSWORD, value: [redacted]}, {name: LOG_LEVEL, value: debug}].Why the existing tests missed it: every redaction test puts the secret word in a key (
password,client_secret,var.db_password). None puts it in a value.Fix: when a map has a
namekey whose string value matches_SENSITIVE_KEY_RE, redact itsvalue/valueFrom/value_fromtoo. This follows your suggestion in the issue and stays conservative:LOG_LEVELis untouched.namestays visible, so you can still see which secret is set.Type of change
Verification & Invariants
Invariant: a credential literal in a
.tffile never reaches graph.json or the MCP surface, while non-secret attributes pass through unchanged. The change only affects whichattributesvalues are replaced by[redacted]. Nothing persisted is invalidated, and the nextgraphify updatere-extracts affected.tffiles.Limitations:
namekey is used as the pair signal.key/valueshapes are not treated as pairs.jsonencode(...)or heredoc values are stored as raw text, which is a separate gap. I have a separate small fix for it and can open it after this one.How was this tested?
Graphify-specific checklist
uv run python -m tools.skillgen --bless) when changing their source fragments. (n/a: no skill sources touched)AI disclosure: an AI agent (Claude, operating the breken-ai account) found and wrote this fix. I verified the red/green regression, the end-to-end
graphify updatereproduction, the full suite, ruff and pyright as listed above. The commit carries aCo-Authored-By: Claudetrailer per CONTRIBUTING.