Repository navigation
feat(gate): scan chosen folders for terms, and project codes outside their folder - #11
Merged
Merged
Conversation
…their folder
The leak check only looked at forbidden terms in audience: customer docs. A
customer name in an internal doc in a customer-neutral folder passed, which
is the slip a team brain most needs caught. Three opt-in gate keys, all off
by default, so existing brains behave as before:
- term_scan_prefixes: folders whose docs are term-scanned whatever their
audience. "bms" and "bms/" both match bms/..., never bmsx/....
- project_prefix: each tracked subfolder under it is a project code, and a
code in any doc outside its own subfolder is a gate-leak:code error,
matched as a whole word ('_' counts as a separator, so a code in a
snake_case file name is caught) and redacted in the report. Files directly in
the project folder, such as its _index.md, may list every code. The
check needs no terms file, so it also runs in CI where that file is
absent, such as on fork pull requests, which get no secrets.
- project_code_pattern: a regex a subfolder name must fully match to count
as a code, for a project folder that also holds non-customer topics
(otherwise a folder named after a regulation flags every mention of it).
An invalid regex fails fast like the other gate keys.
Both path-keyed scans run in the text pre-pass with the secret scan, so
they also cover exempt files and _index.md, which carry no frontmatter.
Codes come from the tracked files, so a local-only folder never changes
the result. Term and code needles are normalised once; the code regex runs
only after a plain substring hit, since its lookbehind makes a full scan
slow. Per-file paths are made POSIX where they are built, so prefix checks
also hold on Windows.
…ders With gate.project_prefix set, a project code in frontmatter counts like one in the body, so the ripple step's related: entries and project: ranking would make km fail its own gate. Ripple now skips paths under a project folder for docs outside it, and a smoke case pins that related: counts.
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The gate's
leakcheck scans forbidden terms only inaudience: customerdocs. A customer name in aninternal doc in a customer-neutral folder passes CI, and that is the slip a team brain most needs
caught. The terms file is gitignored, so CI never has it, and fork PRs get no secrets to supply it.
Change
Three opt-in gate keys. With all three unset, the gate behaves exactly as before.
term_scan_prefixes(list): folders whose docs are term-scanned whatever their audience.bmsandbms/both matchbms/..., neverbmsx/....project_prefix(str): each tracked subfolder under it is a project code. A code in any doc outsideits own subfolder is a
gate-leak:codeerror. It matches whole words, treating_as a separator,and the code is redacted in the report. Files directly in the project folder, such as its
_index.md, may list every code. This check needs no terms file, so it also runs in CI, fork PRsincluded.
project_code_pattern(regex): a subfolder name must fully match it to count as a code. This is fora project folder that also holds non-customer topics; without it, a folder named after a regulation
flags every mention of that regulation. An invalid regex fails fast.
Both path-keyed scans run in the text pre-pass with the secret scan, so they also cover exempt files
and
_index.md. Codes come from the tracked files, so a local-only folder never changes the result.The needles are normalised once. The code regex runs only after a plain substring hit, because its
lookbehind makes a full scan slow (measured about 34 times faster on an 840-doc brain). Per-file paths
are made POSIX where they are built.
Verification
codes, pre-pass coverage, single report, word boundary,
_separator and pattern. Each mutationfails at least one test.
mainplus 11 open PRs, withproject_prefixand a pattern: nofalse positives. A planted code in a neutral doc was reported and redacted.
projects/cra/would flag every "CRA" in the brain. Thatcase is why
project_code_patternexists.A release is a separate version bump.