Skip to content

fix: suppress the false alert on AWS batch logging - #56

Merged
catinspace-au merged 2 commits into
mainfrom
fix/aws-secret-log-redaction
Sep 30, 2026
Merged

catinspace-au merged 2 commits into
mainfrom
fix/aws-secret-log-redaction

Conversation

@catinspace-au

@catinspace-au catinspace-au commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

CodeQL flags the per-secret error log in the AWS provider's batch fetch as clear-text logging of a secret. It isn't one. Code scanning alert #23 (py/clear-text-logging-sensitive-data) at src/scalo/secrets/providers/aws.py:645.

  • The flagged value is SecretId. CodeQL treats any .get() keyed on a name containing "secret" as sensitive, and BatchGetSecretValue fills SecretId with the name or ARN the caller asked for. An Errors entry holds SecretId, ErrorCode and Message, never a SecretString.
  • The flagged argument now carries CodeQL's codeql[py/clear-text-logging-sensitive-data] suppression comment, with that reason, on the line above it.
  • New test runs a partial batch failure through the moto emulator with a known fake value and asserts that no scalo log record, at any level, carries it. Adding the batch response to the log makes it fail.
  • The alert will NOT close at merge on its own. This repo runs CodeQL default setup, and its SARIF (main and this PR, CodeQL 2.27.1) carries 43 rules and no py/alert-suppression query, so nothing reads the comment. Closing feat: version check on by default with app-supplied endpoint defaults #23 needs a dismissal or a scanning workflow that honours suppressions.

Code scanning alert #23 flags the per-secret error log in the AWS provider's batch fetch. The flagged value is SecretId, the name or ARN the caller asked for, and a BatchGetSecretValue Errors entry never carries a secret value. The line now carries CodeQL's suppression comment with that reason, and a new test asserts that no log record from a partial batch failure contains the secret value.
Both high advisories (CVE-2026-97687, CVE-2026-97689) and the medium GHSA-gh4c-6fx4-qh6g were published on 2026-09-30 and are fixed in urllib3 2.8.0, which pip-audit now requires. Lockfile only.
@catinspace-au
catinspace-au merged commit cf73c5d into main Sep 30, 2026
17 checks passed
@catinspace-au
catinspace-au deleted the fix/aws-secret-log-redaction branch September 30, 2026 15:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant