You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
scanner: Harden detection and scan coverage - #120
Separate scan coverage from findings and enforce bounded inputs and output safety.
Fix CI fixtures, preserve portable filename decoding tests, and add paired false-positive regressions.
Shorten the README and remove the review documents.
Compatibility
Reports can return INCOMPLETE; --fail-on-unscannable applies in every exit mode.
Corrected matches can change baseline fingerprints, but the baseline schema stays unchanged.
Incomplete scans cannot update baselines.
Input, line, path, and finding limits can stop oversized scans.
Validation
Local debug and release suites each pass 320 tests.
Clippy with -D warnings, formatting, and Rust 1.85 checks pass.
Local self-scan passes with .DS_Store excluded; baseline regeneration produces no drift.
The synthetic corpus contains 39 cases: 20 credentials and 19 non-credentials.
The latest fixes leave the baseline unchanged.
Check the PR checks for cross-platform CI results.
The synthetic corpus does not establish production precision or recall.
Large workspace scans can reach the finding budget and exit 2 without a report.
Container execution and production runtime validation remain outside the tested scope.
Match complete credentials and make incomplete coverage explicit.
Bound scan resources, protect output writes, and validate configuration.
Add paired accuracy cases, regression tests, and workload measurements.
Baseline reviewed synthetic fixtures and document remaining CI and
large-repository scan limits.
Assisted-by: GPT-6.1 Sol
Signed-off-by: PiX <69745008+pixincreate@users.noreply.github.com>
Hardens secret detection, scan coverage reporting, resource limits, configuration validation, and output safety across the CLI, hooks, and GitHub Action.
Changes:
Improves credential matching, Git scanning, coverage reporting, and SARIF output.
Adds bounded resource handling and safer report/baseline writes.
Expands regression, accuracy, integration, and workload validation.
Use private test directories and match complete credential expressions.
Bound MongoDB matches and share Git object-size queries.
Apply line limits to file content, including final carriage returns.
Shorten the README and remove review documents.
Refresh the baseline with reviewed synthetic fixtures.
Assisted-by: GPT-6.1 Sol
Signed-off-by: PiX <69745008+pixincreate@users.noreply.github.com>
Count filesystem visits across all operands and preserve findings when
Git patches include gitlinks. Set output permissions before publication
so a restrictive umask cannot remove owner access.
Limit control-character filename fixtures to Unix and keep decoding
checks portable. Add paired regressions for reported false positives.
Assisted-by: GPT-6.1 Sol
Signed-off-by: PiX <69745008+pixincreate@users.noreply.github.com>
Unescaped control characters in file paths can manipulate terminal output
src/scanner/staged.rs:241
These newly decoded control bytes are retained in Finding.file_path, while non-verbose output interpolates that path directly into the terminal. A repository-controlled filename containing BEL, backspace, form feed, or vertical tab can therefore manipulate console output; keep the decoded path for Git lookup/report identity, but escape control characters at every human-readable output boundary.
Documentation overstates secret redaction for verbose show-secrets output
README.md:27
This is not true for --verbose --show-secrets: verbose mode prints the generated report to the console, and --show-secrets leaves matched content unredacted. Qualify this guarantee as applying to non-verbose console summaries so users do not expose secrets based on the documentation.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
luhnvalidation.Compatibility
Reports can return
INCOMPLETE;--fail-on-unscannableapplies in every exit mode.Corrected matches can change baseline fingerprints, but the baseline schema stays unchanged.
Incomplete scans cannot update baselines.
Input, line, path, and finding limits can stop oversized scans.
Validation
-D warnings, formatting, and Rust 1.85 checks pass..DS_Storeexcluded; baseline regeneration produces no drift.Check the PR checks for cross-platform CI results.
The synthetic corpus does not establish production precision or recall.
Large workspace scans can reach the finding budget and exit 2 without a report.
Container execution and production runtime validation remain outside the tested scope.