docs(security): say what the scanners cover and what guards the price - #1
Merged
Merged
Conversation
Secret scanning and push protection are now on, and they work by recognising credential formats. The closest thing to a disclosure this project has actually had was not a credential: it was a vendor's price, quoted from their docs into a shipped config file under an agreement that makes pricing confidential and overrides the public-knowledge exclusion. No scanner recognises a price. 0.042 is a float. Push protection would have passed it through, and did, until it was caught by reading. That observation was only in a chat log, which is where useful things go to die. SECURITY.md now separates the two and names the real control: the --pricing design keeps tariffs in operator-supplied config, and a test asserts no shipped entry for that vendor carries a numeric figure in either a price field or its source string. Both halves of that test were verified by injecting a figure and watching it go red: once as a populated price field, once as a price quoted in the prose around one. It is not a test that only looks like it works. CONTRIBUTING gets one line where it matters, under the adapter-config section, because that is the page someone reads before adding a vendor. PLAN.md records the CodeQL decision with its exit condition: kept for actions coverage, Python queries expected to be low yield here, off if a second false positive lands on ordinary work. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Secret scanning and push protection are on now. They recognise credential
formats. The closest thing to a disclosure this project has actually had was
not a credential: it was a vendor's price, quoted from their documentation into
a shipped config file, under an agreement that makes pricing information
confidential and expressly overrides the usual public-knowledge exclusion.
No scanner recognises a price.
0.042is a float. Push protection would havepassed it through without a murmur, and did, until it was caught by reading.
That observation existed only in a chat log. This writes it down where it will
be read.
Changes
(credential formats) from what they do not (contractual confidentiality), and
names the actual control: the
--pricingdesign keeps tariffs inoperator-supplied config, and a test asserts no shipped entry for that vendor
carries a numeric figure.
that is the page someone reads before adding a vendor.
The test was verified, not assumed
test_no_shipped_entry_states_a_figure_for_the_confidential_vendorwas provento fail in both the ways that matter, by injecting a figure and watching it go
red:
input_usd_per_million=0.042givesAssertionError: jev-1.13.0 / assert 0.042 is None.None. Injecting"$0.042 per Mtok input"intoJEV_SOURCEtrips the digit check on thesource string.
Both were reverted and the suite is green. A guard that only looks like it
works is worse than no guard, so it seemed worth proving before writing a
document that points people at it.
CodeQL
Kept for its
actionscoverage rather than its Python coverage. Workflowscript injection is a real class of bug and
ci.ymlis where it would hide.The Python queries are expected to be low yield here: a CLI with no attacker in
its threat model. The first full scan produced one alert, a false positive on a
test assertion that makes no security decision, dismissed with that reasoning.
PLAN.md records the threshold for turning it off: a second false positive on
ordinary work.
Docs only. No behaviour change.