Skip to content

Fix secret-scan false positives in test fixtures - #28

Merged
kwisatzh merged 2 commits into
mainfrom
fix/security-scan-fixtures
Oct 5, 2026
Merged

kwisatzh merged 2 commits into
mainfrom
fix/security-scan-fixtures

Conversation

@kwisatzh

@kwisatzh kwisatzh commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Exempt four reviewed synthetic test-data matches using exact commit/file/rule/line fingerprints.
  • Keep full-history scanning and all default rules enabled; new occurrences still trigger review.
  • Print actionable file/line details while fully redacting matched values.
  • Run scheduled security checks with Go 1.27.1, which contains the fix for the timed-fuzz cancellation race in testing: Fuzz testing with fuzztime flag sometimes fails incorrectly with "context deadline exceeded" golang/go#75804. Keep all five two-minute fuzz targets and race tests unchanged. The module minimum and normal Go 1.26 CI stay unchanged.

Verification

  • Reproduced the four matches in the scheduled job history; the exact exceptions make that history scan pass.
  • Positive control: the same privacy-test sentinel still fails scanning outside its historical exception.
  • The first hosted repair run passed vulnerability and secret scanning, then hit the upstream deadline race during fuzzing (run 37376605483). No crashing corpus was reported; the same two-minute target passed locally with Go 1.26.8.
  • Verified the upstream fix in the published Go 1.27.1 source before updating the security runner.
  • Workflow YAML parses and git diff --check passes.
  • Full hosted security workflow and PR checks must pass on the final head before merging.

No application code, dependencies, minimum Go version, or contributor PRs changed.

@kwisatzh

kwisatzh commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Validation complete on c90aadd: all normal PR checks passed, and the full security workflow passed with every test step executed: https://github.com/llm-measurement/fleetdiff/actions/runs/37378194267 . This includes the vulnerability check, full-history secret scan, all five unchanged two-minute fuzz targets, and race tests. The earlier failed run remains recorded; the corrected security job uses the published Go fix for the deadline race.

@kwisatzh
kwisatzh merged commit ab88d59 into main Oct 5, 2026
12 checks passed
@kwisatzh
kwisatzh deleted the fix/security-scan-fixtures branch October 5, 2026 21:59
@kwisatzh

kwisatzh commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Post-merge verification also passed on main (ab88d59): https://github.com/llm-measurement/fleetdiff/actions/runs/37379579358 . Every security step executed successfully, including all five extended fuzz targets and race tests. Normal main CI and CodeQL also passed. No release is required for this workflow-only repair.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant