Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

chore: tracker-leak pre-push scanner needs CI-side backstop + wider coverage

Đang mở
#1,142 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
48/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
git, github-actions, typescript
Lĩnh vực
ci-cd, devtools, security

Hướng nghiên cứu

Bắt đầu với script/check-tracker-leaks.ts, sau đó kiểm tra .github/workflows/* và các hostname trong .claude/rules/* mà nó tham chiếu. So sánh các pattern pre-push hiện có với cơ chế backstop CI được đề xuất và phạm vi bao phủ RULES rộng hơn; được xem là hoàn tất khi các kiểm tra đã thống nhất chạy trong CI và phạm vi được tài liệu hóa khớp với các pattern được áp dụng.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Found during v0.9.7 release review (CTO + Chaos Gremlin personas), and already self-disclosed in the originating commit (205a953d62 / PR #1085).

The pre-push tracker-leak scanner (script/check-tracker-leaks.ts) currently:

  • Covers exactly two patterns: Jira key (\bAI-\d+) and the altimateai.atlassian.net hostname.
  • Has no CI-side mirror — the originating PR deferred this because the session's token lacked workflow scope to add .github/workflows/*.
  • Is bypassable via SKIP_TRACKER_CHECK=1 or simply never installed (git config core.hooksPath .husky is opt-in).

A contributor merging via the GitHub UI, the API, or without the hook installed gets zero enforcement today. The scanner's own docs ('public repo hardening') can read as more comprehensive than it is.

Suggested follow-up:

  1. Add a CI job mirroring the pre-push check (needs a workflow-scoped token).
  2. Widen RULES to cover other internal-only hostnames referenced in this repo's own .claude/rules/* (e.g. onealtimate.com), not just the Atlassian one.
  3. Consider whether customer/tenant name patterns or credential-shaped strings (AWS keys, connection strings) belong in scope, or should be a separate secret-scanning tool.
Ngôn ngữ chính
TypeScript
Star
805
Fork
122
Merge trung bình
2 ngày 10 giờ
Pull request đã merge (30 ngày)
63

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của AltimateAI/altimate-code

Tất cả issue của AltimateAI/altimate-code

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.