Repository navigation
fix(security): load client-leak patterns from org secret, fail closed - #13
Draft
RevealUIStudio wants to merge 1 commit into
Draft
RevealUIStudio wants to merge 1 commit into
RevealUIStudio wants to merge 1 commit into
Conversation
Co-authored-by: Joshua Vaughn <founder@revealui.com>
RevealUIStudio
commented
Oct 6, 2026
RevealUIStudio
left a comment
Owner
Author
There was a problem hiding this comment.
Security soft review: PASS. P0=0 P1=0.
- The literal pattern list is removed from the scanner. No added line, the title, the body or the commit message carries any of it.
- The workflow passes
secrets.CLIENT_LEAK_PATTERNSinto the pinned composite. The job nameClient / prospect name leak scanis unchanged and still triggers onmaster. - Fails closed in CI when the secret is empty. The local fallback
.client-name-watchlist.localis gitignored. - The failing leak-scan check is expected until the org secret is visible to this repo. The
updates.ymlfailure is pre-existing onmaster.
This fixes the tip exposure that #12 introduced on master. Stays draft. No merge until the owner confirms the org secret. Security does not merge, undraft, or promote.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The client / prospect name leak scanner no longer stores its detection list in the public tree.
scripts/check-client-leaks.shloads the literal pattern list at runtime fromCLIENT_LEAK_PATTERNS(multiline, onetag|literal|reasonline per pattern). Behavior stays the same once that secret holds the previous lines..github/workflows/check-client-leaks.ymlpassesclient_leak_patterns: ${{ secrets.CLIENT_LEAK_PATTERNS }}into the pinned shared actionRevealUIStudio/.github/.github/actions/check-client-leaks@8ea1ca5697dfc1f2041aac1368a9dd6d241121ab. The job name staysClient / prospect name leak scan.Fail closed:
CI=trueorGITHUB_ACTIONS=true), an empty or missingCLIENT_LEAK_PATTERNSexits non-zero and names that secret..client-name-watchlist.localfile is an optional fallback. If neither source is present, the script prints a warning and exits 2.The scanner no longer excludes itself. This repo has no
.gitleaks.issues.tomland no workflow consumes one, so there were no committed name rules to relocate. The previous exclusion of that filename was dropped with the self-exclusion. Unrelated gitleaks rules were not present.CI on this PR is expected to fail closed until the org secret
CLIENT_LEAK_PATTERNSexists and is visible to this repo. The old values remain in git history. No history rewrite; that is accepted.Adding coverage: add the line to the
CLIENT_LEAK_PATTERNSorg secret, never to a committed file.