fix(security): sanitize credentials at every output boundary (#2111) - #2112
Merged
Conversation
Adding .gitkeep for PR creation (default mode). This file will be removed when the task is complete. Issue: #2111
konard
marked this pull request as ready for review
July 27, 2026 17:37
Contributor
Author
Working session summaryImplemented and finalized PR #2112, now ready for review. Key results:
This summary was automatically extracted from the AI working session output. |
Contributor
Author
🤖 Solution Draft LogThis log file contains the complete execution trace of the AI solution draft process. 💰 Cost estimation:
📊 Context and tokens usage:
Total: (1.5M + 74.0M cached) input tokens, 180.2K output tokens, $97.615721 cost 🤖 Models used:
📎 Log file uploaded as Gist (20160KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
Contributor
Author
✅ Ready to mergeThis pull request is now ready to be merged:
Monitored by hive-mind with --auto-restart-until-mergeable flag |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #2111.
Problem
Generated output could expose credentials through terminal streams, local and development logs, uploads, GitHub comments, telemetry, or repository artifacts. Sanitizing only individual call sites also missed secrets split across stream chunks and made future publication paths easy to add unsafely.
Solution
Reproduction and regression coverage
Before this change, a credential written in pieces or passed through an unguarded publication path could reach generated output unchanged.
tests/test-credential-sanitization-2111.mjsnow exercises the masking contract, all-match replacement, vendor and generic formats, split chunks, private keys, terminal interception, temporary-file permissions and cleanup, upload bytes, development-log staging, fail-closed behavior, and a 1 MiB performance case.Verification
npx --yes node@24 scripts/run-tests.mjs --suite default— 354 test files passednpm run lintnpx prettier --check <all changed JavaScript, JSON, and Markdown files>npm run check:duplicationgit diff --checkThis is a non-visual security change; screenshots are not applicable.