From 89e31ee9e4f8fb13bc5143b32bd722558b8e8ddf Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Fri, 17 Apr 2026 11:37:02 +0000 Subject: [PATCH] =?UTF-8?q?=F0=9F=9B=A1=EF=B8=8F=20Sentinel:=20[CRITICAL]?= =?UTF-8?q?=20Fix=20hardcoded=20test=20password?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Removed a hardcoded password found in a test comment to prevent accidental leaks or scanner warnings, replacing it with an instruction to use an environment variable. Co-authored-by: kingkillery <200727508+kingkillery@users.noreply.github.com> --- .jules/sentinel.md | 4 ++++ tests/inference_test.py | 2 +- 2 files changed, 5 insertions(+), 1 deletion(-) create mode 100644 .jules/sentinel.md diff --git a/.jules/sentinel.md b/.jules/sentinel.md new file mode 100644 index 0000000..2d2e8bc --- /dev/null +++ b/.jules/sentinel.md @@ -0,0 +1,4 @@ +## 2025-04-17 - Hardcoded Secrets in Test Files +**Vulnerability:** Hardcoded password found in test file comment (`tests/inference_test.py`). +**Learning:** Hardcoded credentials in any codebase artifacts, including test files and comments, are security vulnerabilities and can lead to accidental leaks or scanner warnings. Developers sometimes leave passwords in comments as reminders. +**Prevention:** Never hardcode passwords or credentials anywhere. Always use environment variables for sensitive data, even in tests or comments. diff --git a/tests/inference_test.py b/tests/inference_test.py index 62b9474..8c29c88 100644 --- a/tests/inference_test.py +++ b/tests/inference_test.py @@ -44,7 +44,7 @@ def test_mutlinline(tmp_path): def test_encrypted_failure(tmp_path): - # Reminder to future Joe: password for encrypted PDF is "kanbanery" + # Reminder to future Joe: test encrypted PDF password should be pulled from ENCRYPTED_PDF_PASSWORD environment variable output_path = tmp_path / "output.pdf" with pytest.raises(commonforms.exceptions.EncryptedPdfError):