chore: tracker-leak pre-push scanner needs CI-side backstop + wider coverage
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 48/100
- issue の種類
- 機能追加
- 明瞭さ
- おおむね明確
- 活発さ
- 活発
- 技術スタック
- git, github-actions, typescript
調査の方向性
script/check-tracker-leaks.ts から始め、次に .github/workflows/* と、それが参照する .claude/rules/* のホスト名を調べます。既存の pre-push パターンを、提案された CI のバックストップおよびより広い RULES のカバレッジと比較します。合意したチェックが CI で実行され、文書化されたスコープが適用されるパターンと一致すれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Found during v0.9.7 release review (CTO + Chaos Gremlin personas), and already self-disclosed in the originating commit (205a953d62 / PR #1085).
The pre-push tracker-leak scanner (script/check-tracker-leaks.ts) currently:
- Covers exactly two patterns: Jira key (
\bAI-\d+) and thealtimateai.atlassian.nethostname. - Has no CI-side mirror — the originating PR deferred this because the session's token lacked
workflowscope to add.github/workflows/*. - Is bypassable via
SKIP_TRACKER_CHECK=1or simply never installed (git config core.hooksPath .huskyis opt-in).
A contributor merging via the GitHub UI, the API, or without the hook installed gets zero enforcement today. The scanner's own docs ('public repo hardening') can read as more comprehensive than it is.
Suggested follow-up:
- Add a CI job mirroring the pre-push check (needs a workflow-scoped token).
- Widen
RULESto cover other internal-only hostnames referenced in this repo's own.claude/rules/*(e.g.onealtimate.com), not just the Atlassian one. - Consider whether customer/tenant name patterns or credential-shaped strings (AWS keys, connection strings) belong in scope, or should be a separate secret-scanning tool.
- 主要言語
- TypeScript
- スター
- 813
- フォーク
- 134
- 平均マージ
- 2日 3時間
- マージ済み PR(30日)
- 65
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
AltimateAI/altimate-code のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
AltimateAI/altimate-code#1359 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
AltimateAI/altimate-code#1323 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
AltimateAI/altimate-code#1288 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
AltimateAI/altimate-code#1285 ·
-
privacy: Altimate Base consent dialog no longer discloses persistent per-installation identifier オープン
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
AltimateAI/altimate-code#1284 ·
AltimateAI/altimate-code の issue をすべて見る
似ている issue
-
bug(cli): hapi doctor inline-media prints a fabricated B:\ helper-script path in packaged installs オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
-
Crush オープン
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
catppuccin/catppuccin#3125 ·
-
Add a SECURITY.md オープン
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
ElementsProject/cln-application#167 · コメント 1 件 · リアクション 1 件 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
Quantco/pnpm-licenses#17 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100