Phase 3a: re-point health.zig secret scan onto safety_core.scanSource — detectSecret now returns the first credential/private_key from the shared verdict (one canonical pattern set + suppression matrix), deleting health's private prefixedSecretToken pattern set (duplicate #2 of 3). hasSecretPattern/detectSecret take (gpa, path) so core's per-line suppression applies; tests pass a path; PEM test now requires a real >=40 base64 body per law §3 + a no-body negative. Corpus 2/2 + suite green except the pre-existing profile-heart failure (v1.56.180)
$ koh steal kepr.uk/kepr@2f671a9ea4e5
·
parent: 3d4dfc261c49
discussion
log in to leave a comment.