Skip to content

fix(gitleaks): honor lone string classifications as one label - #2070

Draft
seonghobae wants to merge 1 commit into
mainfrom
autoresearch/20260910-gitleaks-string-label
Draft

seonghobae wants to merge 1 commit into
mainfrom
autoresearch/20260910-gitleaks-string-label

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Gap G-03 (security-gate accuracy): result_classifications iterated a lone string char-by-char, so classifications: "test" never matched "test".

Exact head 11a5aedb6 on base f578d8d96 (origin/main re-fetched, no drift).

Change (minimal, isolated): scripts/ci/filter_gitleaks_sarif.py +12/-3 via _classification_items helper; RED test test_filter_accepts_string_classifications in tests/test_filter_gitleaks_sarif.py.

Evidence (exact-head worktree /private/tmp/nextgap):

  • .venv/bin/python -m pytest tests/test_filter_gitleaks_sarif.py tests/test_codeql_sarif_gate.py -q → 21 passed
  • coverage report → filter_gitleaks 62/24 100%, codeql_gate 87/32 100%
  • interrogate scripts/ci/filter_gitleaks_sarif.py → 100.0%
  • Behavior contract unchanged for list inputs; fail-closed filtering preserved.

@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 18 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 5312ec56-456d-4371-b2e3-85c76b03ca44

📥 Commits

Reviewing files that changed from the base of the PR and between f578d8d and 11a5aed.

📒 Files selected for processing (2)
  • scripts/ci/filter_gitleaks_sarif.py
  • tests/test_filter_gitleaks_sarif.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Fresh admission correction: exact head 11a5aedb6231bd096e4377d499f73172a3a4fb72 is still based on stale f578d8d960177ff113c25fd740619b4a483df300, while protected main is now 37b10243cec3d160ecc9c1be75c71428b160a703; qualifying APPROVED reviews: 0. Restored Draft / Proposed without changing or closing the branch. Preserve the valid delta, then non-force restack it onto the current canonical owner and rerun exact-head Checks before another Ready admission. Prior-head Checks are causal history, not acceptance.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: high High-priority or P1 work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant