fix(plugins): implement structured line-oriented parser for secret redaction - #23
Conversation
There was a problem hiding this comment.
Code Review
This pull request refactors secret scanning and redaction by introducing a centralized redact_secrets function in hf_space/previews.py and integrating it into the PR review memory renderer. It also adds a new test suite for secret redaction safety. Feedback on the changes highlights a security vulnerability where the regex fails to handle escaped quotes inside string literals and misses JSON-style quoted keys, suggesting an updated regex pattern. Additionally, recommendations were made to add the repository root to sys.path in the test suite to prevent import errors and to expand the test matrix to cover these edge cases.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
|
Resolved in commit 592046d.
|
Problem
Secret scanning regex was fragile, failing on escaped quotes inside string values and missing JSON-style quoted keys. The test environment also had path loading issues leading to test failures in CI.
Root cause
The global regex parser was too restrictive and did not handle quotes and escaping logic correctly. Additionally, the python
pandasdependency was missing from optional dev dependencies in the configuration.Final changes
pandasto the optional dev dependencies inpyproject.toml.tests/conftest.py.Security impact
Ensures that credentials, API keys, and sensitive tokens are fully redacted in reviews, previews, and logs, even if they are wrapped in JSON objects or contain escaped quotes.
Compatibility impact
None. Relies on standard Python regex and package tools.
Tests
Expanded the test suite under
tests/test_secret_redaction_safety.pyto cover escaped quotes, empty tokens, newlines, and non-sensitive key variants. All 248 pytest unit tests pass locally.CI
affeb43d298275bf5725b89d36feede6472d0af0: PASS (6 python matrix runs completed successfully on Python 3.10, 3.11, and 3.12).Review findings addressed
Independent verification
Checked and confirmed clean by the Antigravity Verification Agent.
CodeRabbit status
CODERABBIT_NOT_RUN_RUNTIME_SIGILL_WSL_CPU_INCOMPATIBILITYCodeRabbit CLI was installed successfully inside WSL 2 Ubuntu, but execution terminated with SIGILL because of CPU instruction-set compatibility in the current WSL environment. No CodeRabbit review result was produced.
Known limitations
Does not run live provider adapters.
Rollback
Revert this pull request.
Evidence
tests/test_secret_redaction_safety.py