Skip to content

feat: version the credential detection corpus - #47

Merged
kev1n77 merged 1 commit into
mainfrom
codex/secret-corpus
Jul 18, 2026
Merged

kev1n77 merged 1 commit into
mainfrom
codex/secret-corpus

Conversation

@kev1n77

@kev1n77 kev1n77 commented Jul 18, 2026

Copy link
Copy Markdown
Owner

Summary

  • add a versioned shared credential corpus with 36 sensitive field names and 17 textual secret categories
  • compile the Rust export scanner directly from the corpus instead of hardcoded patterns
  • extend coverage for Basic auth, AWS, GitHub, GitLab, Hugging Face, Groq, xAI, Slack, npm, Stripe, and Databricks credentials
  • validate every positive canary and near miss in Rust and the browser fallback
  • verify Capture Policy and the Python sidecar scrub every shared sensitive field name with normalized variants
  • mark SEC-002 complete while leaving SEC-001 log/temp-file canaries and independent security review open

Verification

  • cargo fmt --all -- --check
  • cargo fmt --manifest-path apps/desktop/src-tauri/Cargo.toml -- --check
  • cargo test --workspace --all-targets
  • cargo clippy --workspace --all-targets -- -D warnings
  • cargo test --manifest-path apps/desktop/src-tauri/Cargo.toml --all-targets
  • cargo clippy --manifest-path apps/desktop/src-tauri/Cargo.toml --all-targets -- -D warnings
  • npm run desktop:check (36 tests)
  • npm run desktop:build
  • python -m unittest discover -s sidecars/mitmproxy/tests -v (17 tests)
  • python sidecars/mitmproxy/package_sidecar.py
  • python sidecars/mitmproxy/verify_sidecar_bundle.py sidecars/mitmproxy/dist

@kev1n77
kev1n77 merged commit 7ebd320 into main Jul 18, 2026
9 checks passed
@kev1n77
kev1n77 deleted the codex/secret-corpus branch July 18, 2026 02:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant