Skip to content

feat(enrichment): detect Langfuse public and Hyperbolic API keys - #3321

Merged
loopover-orb[bot] merged 1 commit into
JSONbored:mainfrom
bohdansolovie:feat/secret-scan-langfuse-hyperbolic
Jul 5, 2026
Merged

feat(enrichment): detect Langfuse public and Hyperbolic API keys#3321
loopover-orb[bot] merged 1 commit into
JSONbored:mainfrom
bohdansolovie:feat/secret-scan-langfuse-hyperbolic

Conversation

@bohdansolovie

Copy link
Copy Markdown
Contributor

Summary

  • Add langfuse_public_key rule for Langfuse pk-lf- public API keys (pairs with existing sk-lf- secret rule)
  • Add hyperbolic_api_key rule for Hyperbolic hb_ API tokens
  • Include positive, truncation, and identifier-continuation negative tests

Test plan

  • cd review-enrichment && npm run build && node --test test/secret-scan.test.ts (88 passing)

Made with Cursor

Add high-confidence secret-scan rules for Langfuse pk-lf- public keys and
Hyperbolic hb_ API tokens, with truncation and identifier-continuation
negative tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
@bohdansolovie
bohdansolovie requested a review from JSONbored as a code owner July 5, 2026 02:10
@superagent-security superagent-security Bot added the contributor:flagged Contributor flagged for review by trust analysis. label Jul 5, 2026
@superagent-security

Copy link
Copy Markdown
Contributor

🚨 Contributor flagged. Click here for more info: Superagent Dashboard

@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@loopover-orb loopover-orb Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jul 5, 2026
@loopover-orb

loopover-orb Bot commented Jul 5, 2026

Copy link
Copy Markdown
Contributor

Warning

🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨

⏸️ Gittensory review result - manual review recommended

Review updated: 2026-07-05 02:09:48 UTC

2 files · 1 AI reviewer · no blockers · readiness 73/100 · CI green · clean

⏸️ Suggested Action - Manual Review

Review summary
This adds two focused secret-scan rules and covers the positive, truncation, and identifier-continuation cases called out in the PR description. The changed regexes are locally consistent with the existing rule table style, and the tests exercise the new kinds and confidence without relying on impossible manufactured scanner state. I do not see a reachable correctness break in the provided diff.

Nits — 6 non-blocking
  • nit: review-enrichment/src/analyzers/secret-scan.ts:334 says the Langfuse public key body is UUID-shaped, but the regex accepts any base64url-ish body of length 20+, so either tighten the pattern or make the comment match the broader rule.
  • nit: review-enrichment/test/secret-scan.test.ts:934 uses repeated single-character fake keys, which proves the length boundary but not the documented provider-shaped examples; add one representative mixed-character fixture for each provider to keep the rule contract obvious.
  • review-enrichment/src/analyzers/secret-scan.ts:335: change the comment to something like `// Langfuse public API key: pk-lf- + URL-safe token body.` unless you intend to enforce an actual UUID-shaped body.
  • review-enrichment/test/secret-scan.test.ts:934: add a positive Langfuse fixture containing `_` or `-`, since the rule explicitly permits those characters and the current positive case only proves lowercase alphanumerics.
  • review-enrichment/test/secret-scan.test.ts:942: add a positive Hyperbolic fixture with mixed case and digits so future edits do not accidentally narrow the base62 body.
  • Readiness score is below the configured threshold — Use the readiness panel as advisory maintainer context; the score does not block this PR.
Signal Result Evidence
Code review ✅ No blockers 1 reviewer
Linked issue ⚠️ Missing No linked issue or no-issue rationale found.
Related work ✅ No active overlap found No same-issue or scoped active PR overlap found.
Change scope ✅ 20/20 Low review scope from cached public metadata (no linked issue context).
Validation posture ❌ 5/25 Preflight is holding this PR: the review lane is unavailable, so it is not ready for automated review.
Contributor workload ✅ 10/10 Author activity: 216 registered-repo PR(s), 130 merged, 9 issue(s).
Contributor context ✅ Confirmed Gittensor contributor bohdansolovie; Gittensor profile; 216 PR(s), 9 issue(s).
Gate result ✅ Passing No configured blocker found.
Review context
  • Author: bohdansolovie
  • Role context: outside_contributor
  • Public audience mode: oss maintainer
  • Lane context: Repository registration is not available in the local Gittensory cache.
  • Public profile languages: not available
  • Official Gittensor activity: 216 PR(s), 9 issue(s).
  • PR-specific overlap: none found.
Contributor next steps
  • Explain no-issue PR.
  • Await review-lane availability.
  • Refresh registry data or choose a registered active repo.
  • Link the issue being solved, or explicitly explain why this is a no-issue PR.
Signal definitions
  • Related work = same linked issue, overlapping active PRs, or title/path similarity.
  • Change scope = cached public metadata such as size labels, draft state, and review-burden hints.
  • Validation posture = whether the PR provides enough public validation/test evidence for maintainer review.
  • Contributor workload = public contributor activity and cleanup pressure, not a repo-wide quality failure.
  • Contributor context = public GitHub/Gittensor identity context; non-Gittensor status is not a blocker.

🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed


💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →.

Checked by Gittensory, a quiet PR intelligence layer for OSS maintainers.

  • Re-run Gittensory review

@loopover-orb loopover-orb Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gittensory approves — the gate is satisfied and CI is green.

@loopover-orb
loopover-orb Bot merged commit 25509a9 into JSONbored:main Jul 5, 2026
6 checks passed
JSONbored pushed a commit that referenced this pull request Jul 5, 2026
Add high-confidence secret-scan rules for Langfuse pk-lf- public keys and
Hyperbolic hb_ API tokens, with truncation and identifier-continuation
negative tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor:flagged Contributor flagged for review by trust analysis. gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant