Skip to content

Fix custom redaction regex isolation - #744

Merged
dmoliveira merged 1 commit into
mainfrom
fix/custom-redaction-regex-isolation
Sep 6, 2026
Merged

dmoliveira merged 1 commit into
mainfrom
fix/custom-redaction-regex-isolation

Conversation

@dmoliveira

Copy link
Copy Markdown
Owner

Summary

  • Execute non-default custom secret-detector regexes in bounded one-shot workers.
  • Preserve the exact built-in detector profile synchronous path and existing traversal/redaction semantics.
  • Enforce request-wide match-span and output-allocation budgets in worker and parent validation, with fail-closed timeout/capacity handling.

Validation

  • npm test (977/977)
  • Focused secret-redaction suite (46/46)
  • npm run build
  • npm run lint
  • make validate
  • pre-commit run --all-files
  • git diff --check

Review

  • Final implementation review: no blockers.

@dmoliveira
dmoliveira merged commit 428e689 into main Sep 6, 2026
3 checks passed
@dmoliveira
dmoliveira deleted the fix/custom-redaction-regex-isolation branch September 6, 2026 07:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant