Skip to content

Potential fix for code scanning alert no. 4: Clear-text logging of sensitive information - #135

Closed
psam21 wants to merge 2 commits into
mainfrom
alert-autofix-4
Closed

psam21 wants to merge 2 commits into
mainfrom
alert-autofix-4

Conversation

@psam21

@psam21 psam21 commented Sep 13, 2026

Copy link
Copy Markdown
Owner

Potential fix for https://github.com/psam21/ns/security/code-scanning/4

To fix this without changing functionality, keep dashboard startup logging but remove any interpolation of sensitive or secret-derived values (password and ideally username too, depending on policy strictness).
Best single fix in blossom/src/index.ts is to replace line 249 with a constant, non-sensitive message.

  • File: blossom/src/index.ts
  • Region: around current line 249
  • Change: replace
    logger(\Dashboard started with username=${config.dashboard.username} (password length: ${password.length})`); with a static message like logger("Dashboard started");`

No imports, helper methods, or dependencies are required.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

psam21 and others added 2 commits September 13, 2026 10:40
…nsitive information

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@psam21

psam21 commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Closing rather than merging: the fix is already on main.

PR #135 proposed replacing the interpolated dashboard startup log with a
static message. main already carries that exact change at
blossom/src/index.ts:249:

logger("Dashboard started");

GitHub Code Scanning alert #4 (Clear-text logging of sensitive information) is closed — there are currently zero open alerts on this
repository — so the branch's only unique commit is work that has already
landed by another route.

Deleting the branch and this draft.

@psam21 psam21 closed this Oct 2, 2026
@psam21
psam21 deleted the alert-autofix-4 branch October 2, 2026 17:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant