Skip to content

Fail closed on weak Driver runtime credentials - #347

Merged
OziinG merged 1 commit into
mainfrom
cc-240-security-hardening
Aug 29, 2026
Merged

Fail closed on weak Driver runtime credentials#347
OziinG merged 1 commit into
mainfrom
cc-240-security-hardening

Conversation

@OziinG

@OziinG OziinG commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Refs EVNSolution/clever-change-control#240

Summary

  • require at least 32 characters for configured Driver JWT secrets at every runtime dependency gate
  • remove the retired resident-number production test seed and its unused identity secret contract
  • extend the existing redacted scanner with a high-confidence Generic Password rule and narrow fixture allowlist
  • ignore common credential JSON and linked .worktrees/ artifacts

Verification

  • delivery-api: 2,117 tests passed, 108 skipped
  • Prisma generation, lint, typecheck, and build passed
  • compose configuration passed with the existing local secret file linked only for validation
  • scanner regression, ignore hygiene, worktree scan, and 832-commit history scan passed with 0 findings
  • git diff --check

External follow-up

  • delete the retired DSV_DRIVER_IDENTITY_SECRET key from production secret storage under a separately authorized runtime change; this PR stops consuming or documenting it and does not print or mutate production secrets

Remove the retired resident-number test seed instead of preserving another secret path, and extend the existing redacted scanner for high-confidence generic password assignments.\n\nConstraint: Production runtime secrets remain outside Git and may not be printed or rotated by this commit.\nRejected: Add a new scanner dependency | the existing redacted scanner and GitGuardian already cover the required path.\nConfidence: high\nScope-risk: moderate\nDirective: Keep the explicit test-fixture allowlist narrow; do not weaken the 32-character Driver JWT gate.\nTested: 2117 delivery-api tests passed; Prisma generation, lint, typecheck, build, compose config, worktree/history secret scans, scanner regression, ignore hygiene, and git diff --check passed.\nNot-tested: The retired production SSM key was not deleted because that is a separate external secret-store mutation.
@OziinG
OziinG merged commit 8361ba0 into main Aug 29, 2026
6 checks passed
@OziinG
OziinG deleted the cc-240-security-hardening branch August 29, 2026 10:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant