Skip to content

Chore: gate credentials and private addresses in the check script - #2

Merged
SandObserver merged 1 commit into
mainfrom
chore/private-data-gate
Aug 22, 2026
Merged

SandObserver merged 1 commit into
mainfrom
chore/private-data-gate

Conversation

@SandObserver

Copy link
Copy Markdown
Owner

Summary

  • Add a secrets check to scripts/check-dist.mjs over src/ and
    public/api/, the files this repository authors. Covers GitHub, OpenAI-shaped,
    AWS, Google and Slack token patterns, private key blocks, JWTs, and RFC 1918
    addresses. Private addresses stay allowed in Markdown prose, where they are
    documented examples.
  • Skip binary files in the hygiene scan. Image bytes were matching the word list.

public/js/ and public/widgets/ are excluded: they are verbatim copies of the
application and carry its own placeholder values.

Testing
npm run build and npm run check pass. Verified the gate by planting a fake
GitHub token and a 192.168.1.42 address in a stub payload: both were reported
and the run failed. Removing them restored a pass.

Checklist

  • npm run build and npm run check both pass.
  • Product UI is shown by running or capturing it, never recreated in CSS.
  • Any new preview or screenshot carries no private hostnames or real data.
  • Visual changes verified in both colour schemes and both docs themes.
  • Links to the app repo still resolve.

Adds a secrets check over the files this repository authors, covering token
shapes for several providers, private key blocks, JWTs, and RFC 1918 addresses.
Documented examples in prose are allowed; stub payloads and page sources are
not.

Skips binary files in the hygiene scan. Byte sequences in images were matching
the word list and would have failed CI for no reason.
@SandObserver SandObserver added the security Security fix label Aug 22, 2026
@SandObserver
SandObserver merged commit b4670d8 into main Aug 22, 2026
1 check passed
@SandObserver
SandObserver deleted the chore/private-data-gate branch August 22, 2026 23:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Security fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant