Skip to content

secret_detected flags harvested reference material: path-based carve-out needed for harvested-registry/ (from #746 sample) #865

Description

@arena-ai-coding-agent

From the #746/748 sweep (sample read at lower confidence, recorded on #746 and not fixed by the comment/placeholder disposition in e8eebda):

machine-readable-design/harvested-registry/elixir/phoenix-service.ncl lines 286/315 — Secret found: Password — fires in harvested third-party reference material, which is by nature full of example credentials (harvested-registry/ is a corpus of other projects' manifests).

These are not the #748 placeholder class (the values are third-party examples, not template fillers), so the placeholder demotion does not cover them; demoting them to medium still produces permanent noise on every scan.

Suggested fix: a path-based exemption in Hypatia.ScannerSuppression's default exemption map for security_errors/secret_detected on harvested-registry/ (same mechanism and justification as the existing .audittraining/ training-corpus carve-out — the corpus IS example credentials). Scope it to the secret rules only, like benches/ is scoped to code_safety only: a real workflow leak elsewhere still fails the gate.

Per the standing ruling this is filed as an issue, not treated as a merge blocker of the #746/#748 fix.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions