Skip to content

Improve secrets classification and storage evidence#1138

Open
alan747271363-art wants to merge 1 commit into
UnitOneAI:mainfrom
alan747271363-art:improve/secrets-classification-storage-evidence
Open

Improve secrets classification and storage evidence#1138
alan747271363-art wants to merge 1 commit into
UnitOneAI:mainfrom
alan747271363-art:improve/secrets-classification-storage-evidence

Conversation

@alan747271363-art
Copy link
Copy Markdown

Summary

  • add public-by-design and known non-secret shape filters to reduce false positives on publishable client keys, SRI hashes, git SHAs, lockfile hashes, and UUIDs
  • expand current provider prefix coverage and add Kubernetes Secret / base64 decode-and-rescan guidance without printing decoded values
  • add storage protection evidence for HSM/KMS-backed high-sensitivity key material and PII stored in secret managers
  • add log masking and post-exposure persistence checks for leaked credential remediation

Scope notes

Addresses #1105 and the PII/HSM/log-masking portions of #1108 in one scoped update to secrets-management. No real secret values are added; examples use prefixes, placeholders, or type-only reporting.

Official references used:

Validation

Bounty

Skill Improvement / Improver candidate. Payment details can be provided privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant