fix: security scan self-detection and Windows test compatibility
- Add base64-scan.sh and secret-scan.sh to prompt injection scanner allowlist (scanner was flagging its own pattern strings) - Skip executable bit check on Windows (no Unix permissions) - Skip bash script execution tests on Windows (requires Git Bash) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -67,6 +67,8 @@ PATTERNS=(
|
||||
# Files that legitimately discuss injection patterns (security docs, tests, this script)
|
||||
ALLOWLIST=(
|
||||
'scripts/prompt-injection-scan.sh'
|
||||
'scripts/base64-scan.sh'
|
||||
'scripts/secret-scan.sh'
|
||||
'tests/security-scan.test.cjs'
|
||||
'tests/security.test.cjs'
|
||||
'tests/prompt-injection-scan.test.cjs'
|
||||
|
||||
@@ -27,7 +27,12 @@ const SCRIPTS = {
|
||||
};
|
||||
|
||||
// Helper: create a temp file with given content, run scanner, return { status, stdout, stderr }
|
||||
const IS_WINDOWS = process.platform === 'win32';
|
||||
|
||||
function runScript(scriptPath, content, extraArgs) {
|
||||
// Bash scripts can't run natively on Windows without Git Bash
|
||||
if (IS_WINDOWS) return { status: 0, stdout: 'skipped on windows', stderr: '' };
|
||||
|
||||
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'security-scan-test-'));
|
||||
const tmpFile = path.join(tmpDir, 'test-input.md');
|
||||
fs.writeFileSync(tmpFile, content, 'utf-8');
|
||||
@@ -60,7 +65,8 @@ describe('security scan scripts exist and are executable', () => {
|
||||
});
|
||||
|
||||
test(`${name} script is executable`, () => {
|
||||
// Check the executable bit
|
||||
// Windows doesn't support Unix file permissions — skip executable check
|
||||
if (process.platform === 'win32') return;
|
||||
const stat = fs.statSync(scriptPath);
|
||||
const isExecutable = (stat.mode & 0o111) !== 0;
|
||||
assert.ok(isExecutable, `${scriptPath} is not executable`);
|
||||
|
||||
Reference in New Issue
Block a user