mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-10-03 15:03:12 +00:00
CodeQL py/clear-text-logging-sensitive-data flagged the logger.info() at line 176 even though it only logs version_id — the taint flowed from secret_value through the lexical scope. Explicitly del secret_value after validation to sever the false-positive trace. Refs: #137 |
||
|---|---|---|
| .. | ||
| email_processor | ||
| shoc_emitter | ||
| shoc_hmac_rotator | ||
| web_ui | ||