Skip to content

Fix CodeQL findings in jira_secret_monitor.py - #82

Merged
kcjeanjacques merged 1 commit into
masterfrom
fix/codeql-jira-secret-monitor
Aug 3, 2026
Merged

kcjeanjacques merged 1 commit into
masterfrom
fix/codeql-jira-secret-monitor

Conversation

@kcjeanjacques

Copy link
Copy Markdown
Contributor

Summary

  • Escape literal dots in the docs.google.com hostname regexes in scripts/jira_secret_monitor.py so a crafted string like https://docsXgoogleXcom/d/FAKEID can no longer masquerade as a valid Google Docs link. Fixes py/incomplete-hostname-regexp.
  • Redact JIRA_PASSWORD before logging the gottingen_hog command line, which was previously logging the plaintext password at INFO level. Fixes py/clear-text-logging-sensitive-data.

Addresses:

  • NR-560186 (py/incomplete-hostname-regexp)
  • NR-560187 (py/clear-text-logging-sensitive-data)

Test plan

  • python3 -m py_compile scripts/jira_secret_monitor.py passes
  • Re-run CodeQL scan on this branch to confirm both alerts clear

- Escape literal dots in the docs.google.com hostname regexes so
  they can't be satisfied by arbitrary characters (py/incomplete-hostname-regexp).
- Redact JIRA_PASSWORD before logging the gottingen_hog command line
  (py/clear-text-logging-sensitive-data).

@bmgbam bmgbam left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm. "linting failure is on every PR in the past 1.5 years. It's a broken/stale gate. A bit of tech debt that needs to be addressed separately."

@kcjeanjacques
kcjeanjacques merged commit 9da595a into master Aug 3, 2026
6 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants