Skip to content

secret_detected flags harvested reference material: path-based carve-out needed for harvested-registry/ (from #746 sample) #865

Description

@arena-ai-coding-agent

From the #746/748 sweep (sample read at lower confidence, recorded on #746 and not fixed by the comment/placeholder disposition in e8eebda):

machine-readable-design/harvested-registry/elixir/phoenix-service.ncl lines 286/315 — Secret found: Password — fires in harvested third-party reference material, which is by nature full of example credentials (harvested-registry/ is a corpus of other projects' manifests).

These are not the #748 placeholder class (the values are third-party examples, not template fillers), so the placeholder demotion does not cover them; demoting them to medium still produces permanent noise on every scan.

Suggested fix: a path-based exemption in Hypatia.ScannerSuppression's default exemption map for security_errors/secret_detected on harvested-registry/ (same mechanism and justification as the existing .audittraining/ training-corpus carve-out — the corpus IS example credentials). Scope it to the secret rules only, like benches/ is scoped to code_safety only: a real workflow leak elsewhere still fails the gate.

Per the standing ruling this is filed as an issue, not treated as a merge blocker of the #746/#748 fix.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority:p2Normal - queue itscope:repoConfined to this repositorysecuritySecurity posture, secrets, scanning, advisories, supply chainstatus:readyFully specified and ready to be picked up

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions