Skip to content

RTDEV-101452 - Stop publishing TruffleHog raw secrets as evidence - #100

Merged
osaidwtd merged 1 commit into
mainfrom
bugfix/RTDEV-101452-redact-trufflehog-secrets
Oct 1, 2026
Merged

osaidwtd merged 1 commit into
mainfrom
bugfix/RTDEV-101452-redact-trufflehog-secrets

Conversation

@osaidwtd

@osaidwtd osaidwtd commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • TruffleHog findings were attached as signed evidence with Raw / RawV2 (and secret-bearing ExtraData) still present, so anyone who can read the package could read credentials that had only been in the scanned tree.
  • Both converters now publish an allowlist of non-secret fields (detector, source location, Redacted, verification status). The Markdown report no longer prints the raw secret, and the workflow deletes the unsanitized JSONL before jf evd create.
  • The README states that evidence is readable by every package reader and must not contain secret material.

Test plan

  • python3 -m unittest test_sanitize_trufflehog.py in examples/trufflehog (allowlist, markdown without raw secrets, redacted-echoes-raw, fixture credentials absent from trufflehog.json)
  • CI / workflow dispatch of Trufflehog evidence integration example still attaches evidence, and the predicate does not contain Raw or RawV2

Made with Cursor

@osaidwtd
osaidwtd merged commit f61d951 into main Oct 1, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants