procurement-ingest/lambdas
Adam Moussa 9a3784c471
fix(webhook): drop kid from rotator test_ok log (CodeQL clear-text-logging FP)
GHAS CodeQL flagged py/clear-text-logging-sensitive-data (high) at
_test_secret's success log because head["kid"] is subscripted from the
same parsed-secret dict that holds head["secret"] — the taint tracker
can't tell the non-secret key id from the secret. The secret value is
never logged. Rather than dismiss the alert (fragile; re-alerts on line
moves), remove the flow: kid is already logged at stage time in
_create_secret and version_id correlates the steps, so the test_ok log
keeps only event + version_id. Also hardens against a future edit that
swaps the logged field.
2026-07-24 16:51:55 -04:00
..
api feat(api): Redocly lint gate + SHOC-themed /docs (Redoc theming, topbar, collapsible samples) (#130) 2026-07-24 18:04:30 +00:00
po chore(deps): bump boto3 (#122) 2026-07-21 16:06:26 -04:00
shared feat(api): procurement-api read stack + OpenAPI docs (SHOC reconciliation path) (#127) 2026-07-23 19:32:20 -04:00
wo fix(webhook): drop kid from rotator test_ok log (CodeQL clear-text-logging FP) 2026-07-24 16:51:55 -04:00