Skip to content

fix(signals): redact windows home paths in public PR packets - #514

Merged
JSONbored merged 1 commit into
mainfrom
codex/fix-vulnerability-in-public-safe-pr-packets
Jun 10, 2026
Merged

fix(signals): redact windows home paths in public PR packets#514
JSONbored merged 1 commit into
mainfrom
codex/fix-vulnerability-in-public-safe-pr-packets

Conversation

@JSONbored

Copy link
Copy Markdown
Owner

Motivation

  • Public-safe PR packet text and the CLI safety gate were not rejecting Windows home-directory paths that use normal backslashes (e.g. C:\Users\alice\...), which could leak local workspace paths in copy-paste PR text.

Description

  • Strengthen the server-side public-safety check by updating isPublicSafeText to detect Windows home paths with either \ or / separators (in src/signals/local-branch.ts).
  • Apply the same Windows-path handling to the MCP CLI final safety gate by updating isUnsafePublicPacketText (in packages/gittensory-mcp/bin/gittensory-mcp.js).
  • Add regression tests that verify Windows home paths are removed/rejected from packet titles and validation lines (in test/unit/local-branch.test.ts) and that server-provided packet markdown containing a normal C:\Users\... path is refused by the CLI test (in test/unit/mcp-cli.test.ts).

Testing

  • Ran unit tests: npm test -- --run test/unit/local-branch.test.ts test/unit/mcp-cli.test.ts, and all targeted tests passed.
  • Ran type checking: npm run typecheck (tsc --noEmit) with no errors.
  • Ran repository checks: git diff --check produced no issues.

Codex Task

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jun 9, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
gittensory-ui c671033 Commit Preview URL

Branch Preview URL
Jun 10 2026, 08:37 AM

@ghost

ghost commented Jun 9, 2026

Copy link
Copy Markdown

Note

Gittensory Gate skipped

PR closed before full evaluation. No late first comment was created.

Signal Result Evidence Action
Gate result ⚠️ Skipped #514 is no longer open. No action.

Checked by Gittensory, a quiet PR intelligence layer for OSS maintainers.

@ghost ghost added the gittensory:reviewed label Jun 9, 2026
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@JSONbored JSONbored self-assigned this Jun 10, 2026
@JSONbored JSONbored changed the title Fix Windows home path redaction in public PR packets fix(signals): Fix Windows home path redaction in public PR packets Jun 10, 2026
@github-actions github-actions Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jun 10, 2026
@JSONbored JSONbored changed the title fix(signals): Fix Windows home path redaction in public PR packets fix(signals): redact windows home paths in public PR packets Jun 10, 2026
@JSONbored
JSONbored force-pushed the codex/fix-vulnerability-in-public-safe-pr-packets branch from bde5915 to c671033 Compare June 10, 2026 08:35
@JSONbored
JSONbored merged commit 6f55381 into main Jun 10, 2026
10 checks passed
@JSONbored
JSONbored deleted the codex/fix-vulnerability-in-public-safe-pr-packets branch June 10, 2026 08:38
@github-project-automation github-project-automation Bot moved this from Todo to Done in gittensory - v1 roadmap Jun 10, 2026
@JSONbored JSONbored added the gittensor:feature Gittensor-scored feature linked to a feature issue — scores a 0.25x multiplier. label Jun 10, 2026
@github-actions github-actions Bot mentioned this pull request Jun 10, 2026
12 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. gittensor:feature Gittensor-scored feature linked to a feature issue — scores a 0.25x multiplier.

Projects

No open projects
Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant