Skip to content
This repository was archived by the owner on Jun 5, 2025. It is now read-only.
This repository was archived by the owner on Jun 5, 2025. It is now read-only.

[Task]: Suspicious commands needs its own pipeline #1039

Description

@lukehinds

Description

Suspicious commands is not implemented into the pipeline, its instead hooking into the main pipeline output:

https://github.com/stacklok/codegate/blob/main/src/codegate/pipeline/comment/output.py#L54

It should instead be a pipeline object in the same way as PII, secrets etc.

Additional Context

No response

Activity

  1. therealnb commented on Feb 13, 2025

    @therealnb

    The code was generally in the right place and generally working. Secrets and PII were being found, but this was real.

    Shell languages were not being recognised, this is alleviated here https://github.com/stacklok/codegate/pull/1043/files#diff-f7211151eec890242ec818bcdda3b3a175dda1c686533e679771037692952d5fL141

    In copilot edits, the deltas were being passed as snippets. We have alleviated that here https://github.com/stacklok/codegate/pull/1043/files#diff-0658dbd5db53af1b59ad53ac8ce9dc0ba40042abea62cce7f6b04eebf3fa4cffR63
    So that suspicious commands will not be applied to the main programming languages.

    Both of these will have corner cases, but these fixes offer a low impact set of changes.

  2. therealnb commented on Feb 13, 2025

    @therealnb

    Also reported this #1044
    CC @jhrozek

  3. therealnb commented on Feb 17, 2025

    @therealnb

    Note that we had to disable this code #1073

    It is now unclear where this code should go.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions