Repository navigation
fix(hooks): kv-detect 가 TS 타입 선언(token: string,)을 시크릿으로 잡던 것 — 타입 자리만 지우고 값 대입은 그대로 잡아요 - #30
Merged
Merged
Conversation
…리만 지우고 값 대입은 그대로 잡아요
kv-detect 는 키 이름 뒤 `:` 를 값의 시작으로 읽어서 타입 자리가 값이 됐어요. 실측(one-tenth):
`token: string,` · `messageFor?(target: UserTarget, token: string, platform: Platform)` 이
"CRITICAL 위반 1건" 이 됐고, 그 프로젝트는 매 커밋 오탐을 피하려고 sensors.mode 를 warning 으로
내렸어요 — 시크릿 안전망 전체가 경고로 내려간 셈이에요.
ERE 에는 lookahead 가 없어서 표 행 하나로는 "타입이면 빼라" 를 못 써요. 그래서 kv-detect 를 돌리기
전에 줄에서 `키: 타입` 조각만 지워요 (줄 수 불변 — 줄 번호가 원본과 같아요).
- ① 원시 타입 (string·number·String·Int …) ② `?:` ③ 타입 이름 + `, ; ) | & < > [`
④ 줄 끝 대문자 낱말(숫자 섞이면 제외). `=` 는 일부러 종결자에서 빼서 `token: Foo = "…"` 의 대입은 남겨요
- `common.sh` 에 `goax_secret_scan_file` — 파일 하나를 `줄번호 TAB 라벨` 로 검출 (내용은 안 내요).
critical-rule-grep 은 이 함수 하나로 파일을 읽어요
- 새 프로브 예시 `secret-scan-typed.sh` — 타입 옆 시크릿 값은 막는지(네거티브) + 타입 선언만은
통과하는지(오탐 회귀)를 같이 재요
smoke §41: 타입 선언 픽스처(TS 인터페이스·시그니처·제네릭·유니온·Kotlin/Swift) 통과,
값 대입 6종(`: string = "…"` · `{ token: "…" }` · `= "…"` · YAML 2종 · 같은 줄 타입+값) 차단, 프로브 PASS.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C8rZ6V3FW3nwYA9T7iygPd
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
무엇이 좋아지나
token: string,·messageFor?(target: UserTarget, token: string, platform: Platform)이 "CRITICAL 위반 1건" 이 됐고, 매 커밋 오탐을 피하려고 그 프로젝트는sensors.mode를warning으로 내렸어요 — 시크릿 안전망 전체가 경고로 내려간 거예요const token: string = "…",{ token: "…" },apiKey = "…", YAMLpassword: hunter2xyz, 같은 줄에 타입과 값이 같이 있는 경우까지secret-scan-typed.sh— 타입 옆 시크릿 값은 막는지(네거티브)와 타입 선언만 있는 파일은 통과하는지(오탐 회귀)를 같이 재요어떻게
ERE 에는 lookahead 가 없어서 표 행 하나로 "타입이면 빼라" 를 쓸 수 없어요. 그래서
kv-detect를 돌리기 전에 줄에서키: 타입조각만 지워요 (줄 수 불변이라 줄 번호가 원본과 같아요).token: string·password: String?·secret: number[]?:—apiKey?: Foo, ; ) | & < > [가 뒤따를 때.=는 일부러 빼서token: Foo = "…"의 대입은 남겨요password: Password(숫자가 섞이면 빼지 않아요.secret: Abc123Secret같은 YAML 값을 놓치지 않으려고)common.sh에goax_secret_scan_file을 두고critical-rule-grep은 이 함수 하나로 파일을 읽어요 (출력은줄번호 TAB 라벨, 내용은 안 내요). 발급처 형태(ghp_·sk-·AKIA …) 행은 손대지 않았어요.대가: 따옴표 없는 값 뒤에
,가 오는 YAML flow 표기({token: abc123def, …})는 3번에 걸려 빠져요.범위 밖:
const token = getToken()처럼=뒤가 식(expression)인 경우의 오탐은 이 PR 이전과 같아요.바뀐 파일
templates/default/.ax/scripts/bash/common.sh—goax_secret_type_strip_script·goax_secret_scan_filetemplates/default/.ax/hooks/pre-commit/critical-rule-grep.sh— 시크릿 검출이 위 함수를 써요templates/zero/probe/examples/secret-scan-typed.sh(새 파일) ·templates/zero/probe/README.mdtemplates/default/.ax/hooks/README.md·templates/default/.ax/scripts/bash/README.mdtests/smoke.sh§41검증 (빨강 → 초록)
수정 전 코드에 새 테스트만 얹었을 때 (§41만):
수정 후:
버전·changelog 는 올리지 않았어요 — 열린 #26·#27(0.7.3)·#28(0.7.4) 이 버전을 쥐고 있고 이 PR 과 #31(위치 출력, 이 PR 위에 쌓음)·#29(block-destructive) 이 같이 열려 있어서, 머지 순서가 정해질 때 한 번에 올리는 게 충돌이 적어요.
🤖 Generated with Claude Code
https://claude.ai/code/session_01C8rZ6V3FW3nwYA9T7iygPd