Skip to content

Potential fix for code scanning alert no. 1: Cleartext logging of sensitive information - #10

Merged
sanskarIN merged 2 commits into
mainfrom
alert-autofix-1
Sep 26, 2026
Merged

sanskarIN merged 2 commits into
mainfrom
alert-autofix-1

Conversation

@sanskarIN

Copy link
Copy Markdown
Owner

Potential fix for https://github.com/sanskarIN/RepoDNA/security/code-scanning/1

The safest fix is to stop logging the full secrets data structure in panic messages. Keep the assertion behavior the same (fail if no matching secret is found), but change the error message to include only non-sensitive context (for example, expected rule/path and a count of available findings), rather than {:?} dump of all entries.

In crates/repodna-app/tests/fixtures.rs, update the closure in suspicious_secrets() around line 232:

  • Replace panic!("{rule} in {path}: {secrets:?}")
  • With a sanitized panic message that does not print secrets contents, e.g. panic!("missing expected secret finding: rule={rule}, path={path}, findings_count={}", secrets.len())

No new imports, methods, or dependencies are needed.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…sitive information

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Comment thread crates/repodna-app/tests/fixtures.rs Fixed
@sanskarIN
sanskarIN marked this pull request as ready for review September 26, 2026 10:35
… sensitive information'

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@sanskarIN
sanskarIN merged commit 577a0a9 into main Sep 26, 2026
29 of 31 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants