Skip to content

I1023 — Nothing private reaches a published page

Scan the published graph, the static site and everything the client receives for credential material, private environment values and machine-absolute paths, and fail on a finding without printing it.

READY wave 3 · p0 · implementation profile · parallel safe

Part of capability-graph — One capability graph, two projections, and no second inventory of what this repository can do.

Ready. Every dependency is done, so majordomus plan start I1023 will be accepted.

Objective

Scan the published graph, the static site and everything the client receives for credential material, private environment values and machine-absolute paths, and fail on a finding without printing it.

Why

This milestone publishes a description of everything the repository knows. That is exactly the artifact in which an accidental token or a developer's home directory would travel furthest.

Current state

No such scan exists for the site or the Cockpit data.

Desired state

One check inspects the generated data and the built site, reports findings by location and kind, and runs in CI.

Scope

  • test/cases

Out of scope

  • Printing any secret value while scanning
  • A general secret scanner competing with the repository's existing tooling

Dependencies

What waits on this

Acceptance criteria

  • Known credential variable names, credential-shaped values, raw authorization material and machine-absolute paths are all detected
  • A finding names the location and the kind and never the value
  • A negative test plants a synthetic marker and proves the check finds it
  • The check runs in CI on every change

Validation

  • bash test/run.sh

Evidence required

  • public_scan
  • negative_test

Evidence

None recorded. Every token above needs a command or an artifact behind it before this issue can be completed; narrative is refused.

Risk

A scan tuned to be quiet finds nothing forever. The synthetic marker is what keeps it honest.

Timeline

started
verified
completed

Those three fields, the evidence above and the state of the dependencies are all the status is made of. There is no status field to disagree with them.

Canonical record: .ai/repo/project/issues/I1023.yaml. Read it back with majordomus plan show I1023.