From 533b518553d82dc46b0875938d8762a01df719e4 Mon Sep 17 00:00:00 2001 From: Colin Date: Wed, 10 Jun 2026 00:15:02 -0400 Subject: [PATCH] fix(security-scan): update scanner self-exemption allowlists for renamed suite files The three shell scanners exempt their own adversarial test fixtures by exact filename; the *.security.test.cjs renames broke those entries, so the PR diff scan flagged the scanners' own test payloads. Verified locally with all three scanners in --diff origin/next mode (0 findings) and the security suite (207/207). The .sh files were missed in the original reference sweep because the rename grep filtered to .cjs/.yml/.json/.md extensions. Co-Authored-By: Claude Fable 5 --- scripts/base64-scan.sh | 2 +- scripts/prompt-injection-scan.sh | 8 ++++---- scripts/secret-scan.sh | 6 +++--- 3 files changed, 8 insertions(+), 8 deletions(-) diff --git a/scripts/base64-scan.sh b/scripts/base64-scan.sh index f7c5c7a5a..a64c44aaf 100755 --- a/scripts/base64-scan.sh +++ b/scripts/base64-scan.sh @@ -156,7 +156,7 @@ should_skip_file() { # Skip the scan scripts themselves and test files case "$file" in */base64-scan.sh) return 0 ;; - */security-scan.test.cjs) return 0 ;; + */security-scan.security.test.cjs) return 0 ;; esac # Skip scanner fixture directories — they contain deliberate injection samples case "$file" in diff --git a/scripts/prompt-injection-scan.sh b/scripts/prompt-injection-scan.sh index 78231ef12..5fc8c29fb 100755 --- a/scripts/prompt-injection-scan.sh +++ b/scripts/prompt-injection-scan.sh @@ -69,15 +69,15 @@ ALLOWLIST=( 'scripts/prompt-injection-scan.sh' 'scripts/base64-scan.sh' 'scripts/secret-scan.sh' - 'tests/security-scan.test.cjs' + 'tests/security-scan.security.test.cjs' 'tests/security.test.cjs' - 'tests/prompt-injection-scan.test.cjs' + 'tests/prompt-injection-scan.security.test.cjs' 'tests/verify.test.cjs' 'gsd-core/bin/lib/security.cjs' 'hooks/gsd-prompt-guard.js' 'hooks/gsd-read-injection-scanner.js' - 'tests/read-injection-scanner.test.cjs' - 'tests/security-prompt-injection.test.cjs' + 'tests/read-injection-scanner.security.test.cjs' + 'tests/security-prompt-injection.security.test.cjs' 'tests/fixtures/adversarial/security/' 'SECURITY.md' # These files contain intentional injection examples / security-model prose diff --git a/scripts/secret-scan.sh b/scripts/secret-scan.sh index 82d2b5ab7..9653c8bbd 100755 --- a/scripts/secret-scan.sh +++ b/scripts/secret-scan.sh @@ -218,9 +218,9 @@ should_skip_file() { # Skip the scan scripts themselves and test files case "$file" in */secret-scan.sh) return 0 ;; - */secret-scan-lint.test.cjs) return 0 ;; - */security-scan.test.cjs) return 0 ;; - */security-prompt-injection.test.cjs) return 0 ;; + */secret-scan-lint.security.test.cjs) return 0 ;; + */security-scan.security.test.cjs) return 0 ;; + */security-prompt-injection.security.test.cjs) return 0 ;; tests/fixtures/adversarial/security/*|*/tests/fixtures/adversarial/security/*) return 0 ;; esac return 1