procurement-ingest/lambdas/wo
Adam Moussa 9a3784c471
fix(webhook): drop kid from rotator test_ok log (CodeQL clear-text-logging FP)
GHAS CodeQL flagged py/clear-text-logging-sensitive-data (high) at
_test_secret's success log because head["kid"] is subscripted from the
same parsed-secret dict that holds head["secret"] — the taint tracker
can't tell the non-secret key id from the secret. The secret value is
never logged. Rather than dismiss the alert (fragile; re-alerts on line
moves), remove the flow: kid is already logged at stage time in
_create_secret and version_id correlates the steps, so the test_ok log
keeps only event + version_id. Also hardens against a future edit that
swaps the logged field.
2026-07-24 16:51:55 -04:00
..
email_processor test: consolidate test roots — one loader, shared support, enforced CI floor (phase 8) (#118) 2026-07-20 16:19:15 -04:00
shoc_emitter harden(webhook): resolve /sh-security-review findings (1 confirmed medium + cheap fixes) 2026-07-24 15:23:24 -04:00
shoc_hmac_rotator fix(webhook): drop kid from rotator test_ok log (CodeQL clear-text-logging FP) 2026-07-24 16:51:55 -04:00
web_ui chore(deps): update boto3 requirement in /lambdas/wo/web_ui (#123) 2026-07-21 16:06:29 -04:00