Skip to content

ci: let the private-key scan skip the redactor regex literal - #13

Merged
XavierWu525 merged 2 commits into
mainfrom
ci/private-key-scan-skip-redactor-regex
Sep 8, 2026
Merged

XavierWu525 merged 2 commits into
mainfrom
ci/private-key-scan-skip-redactor-regex

Conversation

@XavierWu525

Copy link
Copy Markdown
Contributor

The codex transcript redactor and the everme/bin bundles built from it
carry the PEM header as a regex literal (BEGIN [A-Z ]*PRIVATE KEY). The
security job matched it as key material and has failed on every plugin
publish since 0.6.2. A real PEM header names the algorithm, so filtering
out the character-class form keeps the check exact.

The codex transcript redactor and the everme/bin bundles built from it
carry the PEM header as a regex literal (BEGIN [A-Z ]*PRIVATE KEY). The
security job matched it as key material and has failed on every plugin
publish since 0.6.2. A real PEM header names the algorithm, so filtering
out the character-class form keeps the check exact.
Both are transitive dependencies with in-range fixes; the security job's
npm audit --audit-level=moderate started failing once the advisories
were published. Lockfile-only change.
@XavierWu525
XavierWu525 merged commit dd96269 into main Sep 8, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant