Sécurité : - ical_url : str → SecretStr | None (masquage dans str/repr/model_dump_json) - En-têtes Authorization/Proxy-Authorization : masquage complet de la valeur - _URL_PATTERN : insensible à la casse (HTTPS:// reconnu) - redact_url() : masquage du nom d'utilisateur (userinfo complet) Configuration : - Sous-configs : Field(default_factory=...) pour rechargement à chaque appel - Suppression du singleton settings (injection de dépendances) - .env.example : ajout AI_PROVIDER et CALDAV_CALENDAR_PATH - Guide : BLOG_RSS_ENABLED → BLOG_ENABLED, AI_MODEL=None par défaut - .secrets.baseline : ligne décalée 5112 → 5117 (faux positif audité) - pre-commit : ajout de pytest aux additional_dependencies du hook mypy Tests : 15 tests (config + redaction) couvrant rechargement, masquage SecretStr, en-têtes Authorization, URL auth intégrée et casse variable. Co-authored-by: opencode/coder <coder@agents.invalid> Co-authored-by: opencode/test-engineer <test-engineer@agents.invalid>
150 lines
2.9 KiB
Plaintext
150 lines
2.9 KiB
Plaintext
{
|
|
"version": "1.5.0",
|
|
"plugins_used": [
|
|
{
|
|
"name": "ArtifactoryDetector"
|
|
},
|
|
{
|
|
"name": "AWSKeyDetector"
|
|
},
|
|
{
|
|
"name": "AzureStorageKeyDetector"
|
|
},
|
|
{
|
|
"name": "Base64HighEntropyString",
|
|
"limit": 4.5
|
|
},
|
|
{
|
|
"name": "BasicAuthDetector"
|
|
},
|
|
{
|
|
"name": "CloudantDetector"
|
|
},
|
|
{
|
|
"name": "DiscordBotTokenDetector"
|
|
},
|
|
{
|
|
"name": "GitHubTokenDetector"
|
|
},
|
|
{
|
|
"name": "GitLabTokenDetector"
|
|
},
|
|
{
|
|
"name": "HexHighEntropyString",
|
|
"limit": 3.0
|
|
},
|
|
{
|
|
"name": "IbmCloudIamDetector"
|
|
},
|
|
{
|
|
"name": "IbmCosHmacDetector"
|
|
},
|
|
{
|
|
"name": "IPPublicDetector"
|
|
},
|
|
{
|
|
"name": "JwtTokenDetector"
|
|
},
|
|
{
|
|
"name": "KeywordDetector",
|
|
"keyword_exclude": ""
|
|
},
|
|
{
|
|
"name": "MailchimpDetector"
|
|
},
|
|
{
|
|
"name": "NpmDetector"
|
|
},
|
|
{
|
|
"name": "OpenAIDetector"
|
|
},
|
|
{
|
|
"name": "PrivateKeyDetector"
|
|
},
|
|
{
|
|
"name": "PypiTokenDetector"
|
|
},
|
|
{
|
|
"name": "SendGridDetector"
|
|
},
|
|
{
|
|
"name": "SlackDetector"
|
|
},
|
|
{
|
|
"name": "SoftlayerDetector"
|
|
},
|
|
{
|
|
"name": "SquareOAuthDetector"
|
|
},
|
|
{
|
|
"name": "StripeDetector"
|
|
},
|
|
{
|
|
"name": "TelegramBotTokenDetector"
|
|
},
|
|
{
|
|
"name": "TwilioKeyDetector"
|
|
}
|
|
],
|
|
"filters_used": [
|
|
{
|
|
"path": "detect_secrets.filters.allowlist.is_line_allowlisted"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.common.is_baseline_file",
|
|
"filename": ".secrets.baseline"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.common.is_ignored_due_to_verification_policies",
|
|
"min_level": 2
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_indirect_reference"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_likely_id_string"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_lock_file"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_not_alphanumeric_string"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_potential_uuid"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_prefixed_with_dollar_sign"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_sequential_string"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_swagger_file"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.heuristic.is_templated_secret"
|
|
},
|
|
{
|
|
"path": "detect_secrets.filters.regex.should_exclude_file",
|
|
"pattern": [
|
|
"\\.venv/.*",
|
|
"\\.git/.*"
|
|
]
|
|
}
|
|
],
|
|
"results": {
|
|
"GUIDE_DEV_PYTHON.md": [
|
|
{
|
|
"type": "Hex High Entropy String",
|
|
"filename": "GUIDE_DEV_PYTHON.md",
|
|
"hashed_secret": "90bd1b48e958257948487b90bee080ba5ed00caa",
|
|
"is_secret": false,
|
|
"is_verified": true,
|
|
"line_number": 5117
|
|
}
|
|
]
|
|
},
|
|
"generated_at": "2026-09-05T21:51:55Z"
|
|
}
|