diff --git a/scripts/_common.py b/scripts/_common.py index 9d87ea2..954caf3 100644 --- a/scripts/_common.py +++ b/scripts/_common.py @@ -119,6 +119,7 @@ def _print( # Resolved at call time, not bound as a default: a caller that replaces # sys.stderr (pytest's capture) must still see the message. print( + # codeql[py/clear-text-logging-sensitive-data] callers pass a secret's key or committed default, never a minted value f"{Path(sys.argv[0]).stem}{f' ({header})' if header else ''}: {msg}", file=file or sys.stderr, ) diff --git a/scripts/creds.py b/scripts/creds.py index 2548814..2732f86 100644 --- a/scripts/creds.py +++ b/scripts/creds.py @@ -313,6 +313,7 @@ def main(argv: list[str] | None = None) -> int: is_tty=sys.stdout.isatty(), setting=os.environ.get(_SHOW_KEY, "") ) for line in summary_lines(values=values, reveal=reveal): + # codeql[py/clear-text-logging-sensitive-data] `make creds` exists to show the admin login, on a terminal only print(line) if write: path = write_summary(values=values, path=ACCESS_SUMMARY_FILE) diff --git a/scripts/tests/test_origins.py b/scripts/tests/test_origins.py index 00b372d..1f17f14 100644 --- a/scripts/tests/test_origins.py +++ b/scripts/tests/test_origins.py @@ -80,8 +80,11 @@ def test_the_per_surface_override_still_wins() -> None: DFE_HYPERDX_APP_URL="http://dfe.example.test", ) - assert "http://dfe.example.test:3000" in found - assert "http://10.0.0.5:3000" not in found + assert found == [ + "http://localhost:3000", + "http://127.0.0.1:3000", + "http://dfe.example.test:3000", + ] @pytest.mark.parametrize(