Skip to content

feat(agentconfig): secret detection, redaction and digests (4/15) - #472

Merged
gusfcarvalho merged 2 commits into
lisa/agent-config/03-classifyfrom
lisa/agent-config/04-redaction
Oct 6, 2026
Merged

gusfcarvalho merged 2 commits into
lisa/agent-config/03-classifyfrom
lisa/agent-config/04-redaction

Conversation

@ccf-lisa

@ccf-lisa ccf-lisa Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Part 4/15 of the agent remote-configuration stack

This stack splits #465 into reviewable layers of at most ~1000 changed lines each (counted without docs/, go.sum and Markdown). The last layer's tree is identical to #465, which already has its review history.

Stacked on #471 (lisa/agent-config/03-classify). Review and merge in order.

What's in this layer

Fourth layer of the agent remote-configuration stack (split from #465): secret detection by key name and by value (linear URL-password scan, token patterns, scheme-less DSNs), Redact/RedactDocument/ScrubSecretText, and Digest over the redacted canonical config.

Size: +1129 -0 = 1129 changed lines (without docs/go.sum).

size-exception: over 1000 LOC because of the tests that cover this layer; the implementation part is well under 1000.

Verification

Each layer builds on its own: go build, go vet (also with -tags integration), golangci-lint run and go test ./... pass, and make swag leaves the tree clean. Integration suites for the packages this layer touches pass locally on testcontainers Postgres.

🤖 Generated with Claude Code

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 0991e8ed-631d-48b7-b36b-d14721d9c529

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: APPROVE

no findings.

Stack (gh stack 484): #469 → #470 → #471 → #472 → #473 → #474 → #475 → #476 → #477 → #478 → #479 → #480 → #481 → #482 → #483

ccf-lisa Bot and others added 2 commits October 6, 2026 08:37
Fourth layer of the agent remote-configuration stack (split from #465): secret detection by key name and by value (linear URL-password scan, token patterns, scheme-less DSNs), Redact/RedactDocument/ScrubSecretText, and Digest over the redacted canonical config.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tector

TestContainsSecretValueLinear asserted a fixed 2s budget, which the race
detector's instrumentation exceeds (about 5s). Keep the linearity check but
scale the budget x10 when built with -race (raceEnabled, set by build tag).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ccf-lisa
ccf-lisa Bot force-pushed the lisa/agent-config/04-redaction branch from 9d54ab3 to 0ffe5eb Compare October 6, 2026 13:06

@gusfcarvalho gusfcarvalho left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ccf-review: APPROVE

no findings.

Stack (gh stack 484): #469 → #470 → #471 → #472 → #473 → #474 → #475 → #476 → #477 → #478 → #479 → #480 → #481 → #482 → #483

@gusfcarvalho
gusfcarvalho merged commit 663acf2 into main Oct 6, 2026
9 checks passed
@gusfcarvalho
gusfcarvalho deleted the lisa/agent-config/04-redaction branch October 6, 2026 15:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant