Skip to content

docs(security): say what the scanners cover and what guards the price - #1

Merged
TMHSDigital merged 1 commit into
mainfrom
docs/price-control-is-not-a-scanner
Sep 22, 2026
Merged

TMHSDigital merged 1 commit into
mainfrom
docs/price-control-is-not-a-scanner

Conversation

@TMHSDigital

Copy link
Copy Markdown
Owner

Secret scanning and push protection are on now. They recognise credential
formats. The closest thing to a disclosure this project has actually had was
not a credential: it was a vendor's price, quoted from their documentation into
a shipped config file, under an agreement that makes pricing information
confidential and expressly overrides the usual public-knowledge exclusion.

No scanner recognises a price. 0.042 is a float. Push protection would have
passed it through without a murmur, and did, until it was caught by reading.

That observation existed only in a chat log. This writes it down where it will
be read.

Changes

  • SECURITY.md gains a section separating what the automated controls cover
    (credential formats) from what they do not (contractual confidentiality), and
    names the actual control: the --pricing design keeps tariffs in
    operator-supplied config, and a test asserts no shipped entry for that vendor
    carries a numeric figure.
  • CONTRIBUTING.md gains one line under the adapter-config section, because
    that is the page someone reads before adding a vendor.
  • docs/PLAN.md records the CodeQL decision with an exit condition.

The test was verified, not assumed

test_no_shipped_entry_states_a_figure_for_the_confidential_vendor was proven
to fail in both the ways that matter, by injecting a figure and watching it go
red:

  1. A populated price field. Injecting input_usd_per_million=0.042 gives
    AssertionError: jev-1.13.0 / assert 0.042 is None.
  2. A price quoted in prose, with the fields left as None. Injecting
    "$0.042 per Mtok input" into JEV_SOURCE trips the digit check on the
    source string.

Both were reverted and the suite is green. A guard that only looks like it
works is worse than no guard, so it seemed worth proving before writing a
document that points people at it.

CodeQL

Kept for its actions coverage rather than its Python coverage. Workflow
script injection is a real class of bug and ci.yml is where it would hide.
The Python queries are expected to be low yield here: a CLI with no attacker in
its threat model. The first full scan produced one alert, a false positive on a
test assertion that makes no security decision, dismissed with that reasoning.
PLAN.md records the threshold for turning it off: a second false positive on
ordinary work.

Docs only. No behaviour change.

Secret scanning and push protection are now on, and they work by recognising
credential formats. The closest thing to a disclosure this project has actually
had was not a credential: it was a vendor's price, quoted from their docs into
a shipped config file under an agreement that makes pricing confidential and
overrides the public-knowledge exclusion. No scanner recognises a price. 0.042
is a float. Push protection would have passed it through, and did, until it was
caught by reading.

That observation was only in a chat log, which is where useful things go to
die. SECURITY.md now separates the two and names the real control: the
--pricing design keeps tariffs in operator-supplied config, and a test asserts
no shipped entry for that vendor carries a numeric figure in either a price
field or its source string.

Both halves of that test were verified by injecting a figure and watching it go
red: once as a populated price field, once as a price quoted in the prose
around one. It is not a test that only looks like it works.

CONTRIBUTING gets one line where it matters, under the adapter-config section,
because that is the page someone reads before adding a vendor.

PLAN.md records the CodeQL decision with its exit condition: kept for actions
coverage, Python queries expected to be low yield here, off if a second false
positive lands on ordinary work.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
@TMHSDigital
TMHSDigital merged commit 5113d4d into main Sep 22, 2026
13 checks passed
@TMHSDigital
TMHSDigital deleted the docs/price-control-is-not-a-scanner branch September 22, 2026 01:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant