fix(security-scan): update scanner self-exemption allowlists for renamed suite files
The three shell scanners exempt their own adversarial test fixtures by exact filename; the *.security.test.cjs renames broke those entries, so the PR diff scan flagged the scanners' own test payloads. Verified locally with all three scanners in --diff origin/next mode (0 findings) and the security suite (207/207). The .sh files were missed in the original reference sweep because the rename grep filtered to .cjs/.yml/.json/.md extensions. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -156,7 +156,7 @@ should_skip_file() {
|
||||
# Skip the scan scripts themselves and test files
|
||||
case "$file" in
|
||||
*/base64-scan.sh) return 0 ;;
|
||||
*/security-scan.test.cjs) return 0 ;;
|
||||
*/security-scan.security.test.cjs) return 0 ;;
|
||||
esac
|
||||
# Skip scanner fixture directories — they contain deliberate injection samples
|
||||
case "$file" in
|
||||
|
||||
@@ -69,15 +69,15 @@ ALLOWLIST=(
|
||||
'scripts/prompt-injection-scan.sh'
|
||||
'scripts/base64-scan.sh'
|
||||
'scripts/secret-scan.sh'
|
||||
'tests/security-scan.test.cjs'
|
||||
'tests/security-scan.security.test.cjs'
|
||||
'tests/security.test.cjs'
|
||||
'tests/prompt-injection-scan.test.cjs'
|
||||
'tests/prompt-injection-scan.security.test.cjs'
|
||||
'tests/verify.test.cjs'
|
||||
'gsd-core/bin/lib/security.cjs'
|
||||
'hooks/gsd-prompt-guard.js'
|
||||
'hooks/gsd-read-injection-scanner.js'
|
||||
'tests/read-injection-scanner.test.cjs'
|
||||
'tests/security-prompt-injection.test.cjs'
|
||||
'tests/read-injection-scanner.security.test.cjs'
|
||||
'tests/security-prompt-injection.security.test.cjs'
|
||||
'tests/fixtures/adversarial/security/'
|
||||
'SECURITY.md'
|
||||
# These files contain intentional injection examples / security-model prose
|
||||
|
||||
@@ -218,9 +218,9 @@ should_skip_file() {
|
||||
# Skip the scan scripts themselves and test files
|
||||
case "$file" in
|
||||
*/secret-scan.sh) return 0 ;;
|
||||
*/secret-scan-lint.test.cjs) return 0 ;;
|
||||
*/security-scan.test.cjs) return 0 ;;
|
||||
*/security-prompt-injection.test.cjs) return 0 ;;
|
||||
*/secret-scan-lint.security.test.cjs) return 0 ;;
|
||||
*/security-scan.security.test.cjs) return 0 ;;
|
||||
*/security-prompt-injection.security.test.cjs) return 0 ;;
|
||||
tests/fixtures/adversarial/security/*|*/tests/fixtures/adversarial/security/*) return 0 ;;
|
||||
esac
|
||||
return 1
|
||||
|
||||
Reference in New Issue
Block a user