Skip to content

secret-in-log is unreliable against sanitized gold traces #2397

Description

@dividedmind

sanitize replaces all values with sequentially numbered tokens like <v1337>. When by coincidence in two different appmaps the same token is masking a secret in one and a log output in another, when using the golden traces skill I've seen the scanner erronously flag this as secret-in-log issue even though the tokens correspond to different strings.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions