Skip to content

fix(security): redact key detector dependency failures - #949

Draft
seonghobae wants to merge 3 commits into
developfrom
fix/key-detector-log-privacy
Draft

seonghobae wants to merge 3 commits into
developfrom
fix/key-detector-log-privacy

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 20, 2026 •

Copy link
Copy Markdown
Collaborator

Security/privacy defect

Protected develop@acdbea6344fe1231c39535b575f4de35e4c607c9 caught librosa.feature.chroma_cqt failures in KeyDetector.detect() with logger.exception(...). That routine log path emitted dependency-controlled exception text and a full traceback, conflicting with BandScope's redacted-by-default logging contract in docs/security/app-security.md.

Exact current identity

  • Protected base: develop@acdbea6344fe1231c39535b575f4de35e4c607c9.
  • Exact head: 6ee9ada2228a91d6e1a0de776347890e8ea82132.
  • Branch: fix/key-detector-log-privacy.
  • Open, Draft, unmerged.

Test-first repair

RED 0871349c75b39082a3354642d9ed67a120387b31 injects /Users/Alice/private-song.wav token=super-secret through a simulated chroma_cqt dependency failure and requires the existing safe empty result plus a stable operation-level diagnostic while rejecting the username/path/file/secret payload from routine logs.

GREEN 83a791ff7b03149efd25dc8cbc3ffeef44c0d586 replaces logger.exception(...) with bounded BandScope-owned operation context plus the exception class. It preserves the empty-result safe-failure contract, audio/key mathematics, and public schema while excluding dependency messages and traceback paths.

Current 6ee9ada2228a91d6e1a0de776347890e8ea82132 records the repaired boundary under CHANGELOG.md Unreleased / Fixed. Current source was independently rechecked against the committed privacy regression rather than inferred from PR prose.

Exact-head verification boundary

Fresh repository workflows are associated with exact head 6ee9ada2228a91d6e1a0de776347890e8ea82132; at the latest refetch they remain queued and are therefore non-passing. No predecessor-head check or review transfers. Any terminal failure must be inspected at its exact job/log/checkout-SHA boundary before another mutation or rerun.

Scope

No audio-analysis algorithm, key-estimation mathematics, input/output schema, dependency, lockfile, model, filesystem/network authority, IPC surface, workflow, credential, vulnerability suppression, or release asset changes belong to this lane.

Canonical protected-base JavaScript dependency remediation remains #783-owned and dependency-lifecycle checkout credential hardening remains #894-owned.

Security Notes

Unexpected third-party failures while key detection processes untrusted decoded audio are untrusted diagnostic input. Routine logging retains only operation and exception-class evidence; raw exception messages and traceback payloads stay outside this repaired boundary. Independent dependency/native log sinks remain governed by their own owners.

Merge gate

Keep Draft until one unchanged resulting exact head has focused/full tests GREEN, exact required owned statement/branch coverage and public docstrings, every applicable repository and central CI/security/SAST/SBOM/supply-chain/release/review gate terminal-success, zero valid unresolved findings, a qualifying independent non-author last-push approval, canonical dependency prerequisites integrated/revalidated where required, and ordinary protected-branch acceptance without bypass.

Queued, pending, skipped-required, cancelled, failed, predecessor-head, protected-base, model-only, self/author, rate-limited, or administrative-bypass evidence is non-passing.

@coderabbitai

coderabbitai Bot commented Aug 20, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 12dfd15e-a2a2-48e2-ae1b-29aab37db867

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@opencode-agent opencode-agent Bot added area: dependencies Dependency or lockfile maintenance area: security Security boundary, hardening, or vulnerability prevention priority: medium Normal-priority or P2 work status: draft Draft pull request type: maintenance Maintenance, build, dependency, or operational upkeep labels Aug 22, 2026
@seonghobae seonghobae added bug Something isn't working type: bug Defect or incorrect behavior labels Sep 7, 2026 — with ChatGPT Codex Connector
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: dependencies Dependency or lockfile maintenance area: security Security boundary, hardening, or vulnerability prevention bug Something isn't working priority: medium Normal-priority or P2 work status: draft Draft pull request type: bug Defect or incorrect behavior type: maintenance Maintenance, build, dependency, or operational upkeep

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant