You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Browse filesBrowse the repository at this point in the historyBrowse files
authored
fix: word-boundary severity matching for critical config keys (#41)
* cowork-bot: fix severity inference to use substring match instead of startswith
Critical keys with embedded sensitive terms (db_password, jwt_token,
app_secret_key, mysql_auth_url, oauth_token, connection_endpoint,
main_api_key_id) were incorrectly classified as WARNING or INFO instead
of BREAKING.
Root cause: _infer_severity_{added,removed,changed}() used
key.lower().startswith(p) which only catches keys that *begin* with
a critical prefix. Real-world config keys overwhelmingly embed the
sensitive term (e.g. 'db_password', not 'password_db'), so the heuristic
almost always missed them.
Fix: change to substring check -- p in key.lower() -- so the severity
gate fires correctly for any key containing a critical term.
Non-sensitive keys (cache_ttl, log_level, port, retry_count) are
unaffected since none of the critical terms appear as substrings.
Regression tests: 11 new cases in TestSeveritySubstringMatch, including
an end-to-end diff_configs assertion that has_breaking fires.
114/114 tests pass; ruff clean.
* cowork-bot: seed cowork-auto-pr.yml workflow for automated PR creation
* cowork-bot: fix severity inference with word-boundary matching for critical terms
Supersedes substring match (p in key.lower()) which:
- Fixed nested keys like services.database.password (TRUE positive)
- But over-flagged false positives: author->auth, secretary->secret, tokenizer->token
New algorithm splits flattened keys into words (dot/snake/kebab/camel) and
matches critical terms as contiguous word sequences. Also handles concatenated
forms for multi-word terms (apikey -> api_key).
+30 tests for word-boundary behavior: nested TRUE-positives,
concatenated TRUE-positives, and 10 false-positive regressions.
All 141 tests pass; ruff clean.
* fix(marketing): correct install to self-hosted --index-url (package not on public PyPI); remove false PyPI badge
* fix: replace dead --index-url install with verified-working git+ (2 occurrences)
---------
Co-authored-by: cowork-bot <cowork-bot@revenueholdings.dev>
Co-authored-by: DevForge Engineer <engineer@devforge.dev>
--body "Automated improvement PR from the Cowork repo-improver rotation (one coherent senior-dev improvement per run; see individual commit messages). Subsequent runs push additional commits to this PR rather than opening new ones."
26
+
else
27
+
echo "Open PR already exists for $GITHUB_REF_NAME — nothing to do."
0 commit comments