mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-10-01 05:23:12 +00:00
GHAS CodeQL flagged py/clear-text-logging-sensitive-data (high) at _test_secret's success log because head["kid"] is subscripted from the same parsed-secret dict that holds head["secret"] — the taint tracker can't tell the non-secret key id from the secret. The secret value is never logged. Rather than dismiss the alert (fragile; re-alerts on line moves), remove the flow: kid is already logged at stage time in _create_secret and version_id correlates the steps, so the test_ok log keeps only event + version_id. Also hardens against a future edit that swaps the logged field. |
||
|---|---|---|
| .. | ||
| email_processor | ||
| shoc_emitter | ||
| shoc_hmac_rotator | ||
| web_ui | ||