Skip to content

fix(secret-guard): protect envrc and flaskenv files - #1167

Open
TheGreatAxios wants to merge 2 commits into
refactor-shell-share-transparent-command-peelingfrom
cl-8994-secret-guard-does-not-treat-envrc-or-flaskenv-as-sensitive
Open

TheGreatAxios wants to merge 2 commits into
refactor-shell-share-transparent-command-peelingfrom
cl-8994-secret-guard-does-not-treat-envrc-or-flaskenv-as-sensitive

Conversation

@TheGreatAxios

Copy link
Copy Markdown
Collaborator

Summary

Verification

  • bun test src/permission/classify-security.test.ts src/permission/critique-grep-file-env.test.ts src/permission/gate.test.ts src/plugins/secret-guard-plugin.test.ts src/plugins/secret-guard-shell-symlink.test.ts src/session/approval-resume.test.ts src/shell/literal-path-arguments.test.ts src/shell/run-shell-authz.test.ts passes
  • bun run check passes

Fixes CL-8994

@linear-code

linear-code Bot commented Sep 25, 2026

Copy link
Copy Markdown

CL-8994

@TheGreatAxios
TheGreatAxios force-pushed the refactor-shell-share-transparent-command-peeling branch from 01f36b0 to bcc92d4 Compare September 25, 2026 12:50
@TheGreatAxios
TheGreatAxios force-pushed the cl-8994-secret-guard-does-not-treat-envrc-or-flaskenv-as-sensitive branch from f9a7859 to e86165f Compare September 25, 2026 12:50
Quoted -c payloads behind fish, busybox, csh, pwsh, and cmd /c stayed
one token, so auto mode default-allowed secret reads including .env.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant