zscripts-token-savers/tests/sanitization-patterns.psd1
Kelly Michels 732a448be5
feat: add zmerge and zpull — fleet-wide PR merging and checkout sync (#79)
* feat: add zmerge and zpull

Two commands that were private-only until now. They turned out to be useful
beyond the fleet they were written for, so they are manifested for publication
and removed from the sanitization denylist's private-only list.

  zmerge   merge every pull request across the org that is genuinely ready -
           MERGEABLE/CLEAN and not a draft - re-checking each one immediately
           before and after every merge, because merging into a default branch
           can conflict a sibling PR in the same repository. Dry run by
           default; -Execute or -e merges.

  zpull    zmerge, then git pull --ff-only in every checkout the merges
           affected. Skips a checkout that is dirty or is not on its default
           branch rather than guessing at it.

WHY THEY COULD BE PUBLISHED NOW. zmerge carried a hardcoded list of sixteen
repository names, which was both the reason it could not be published and a
bug: the org has thirty active repositories, so it scanned about half and
reported "Nothing open to merge" while a ready pull request sat in one it had
never heard of. It asks GitHub now, and the names went with the list.

Get-FleetRepos throws rather than returning an empty list when gh fails,
because a tool that quietly scans nothing prints the same reassuring line as
one that scanned everything and found nothing.

-e is an alias for -Execute on both, the way -s already works for -Scan.

Also: __pycache__/ is gitignored. scripts/plaintext_twins.py creates it on
every run and it was showing up as untracked work.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: CRLF the new scripts, as .gitattributes pins them

zmerge.ps1, zpull.ps1 and zpull.cmd went in with LF endings. .gitattributes
pins *.ps1 and *.cmd to eol=crlf precisely so CHECKSUMS.txt can hold one hash
per file rather than one per platform - so git handed CI a CRLF checkout while
the manifest carried hashes taken from my LF copies, and the three new files
were the only ones that failed.

Local verification passed and CI did not, which is the tell: the manifest was
generated against bytes that only existed on this machine.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-12 15:52:18 -05:00

53 lines
3.5 KiB
PowerShell

<#
Patterns the PUBLIC repo must never contain.
Extracted from Sanitization.Tests.ps1 so that the test here and the
publisher in the private tree read ONE list instead of keeping two.
They had two, and they disagreed: the publisher's scan looked only for
secrets - keys, private-key blocks, ssh targets - while these rules are
about IDENTITY: internal project names, product domains, private-only
script names, operator paths.
So the publisher reported "clean" on files this suite rejects, and would
have published a tree that fails the public repo's own tests
(evo.scripts#106). One list, and that cannot drift apart again.
A denylist proves the absence of KNOWN patterns, not the absence of
secrets. It is a regression net for a specific recurring mistake, not a
substitute for reading what you publish. Add a pattern whenever a new
private identifier appears; a stale entry costs nothing.
Kept narrow on purpose: "evomedia.net" alone is legitimate here - the
attribution header and the repo URL both carry it - so only the drive
path and specific internal hosts are matched.
#>
@{
Denied = @(
@{ Name = 'private project name'; Pattern = '\b(EvoCivilCode|EvoPlatform|DocketMail|SmartPlant\w*|ProvenSheet|evoehs|evoproven|evoaicc|evolocate|evoplatform)\b' }
# The current spellings, which the line above never saw: a dot or a
# hyphen breaks the word and an underscore hides the boundary, so
# evo.ehs, evo-ai and evoehs_app all passed (evo.scripts#138 in the
# private tree). Internal issue references travel with them.
@{ Name = 'current product name'; Pattern = '(?i)\bevo[.-](ehs|ai|edge|locate|proven|platform|civilcode|scripts)\b|\bevoehs' }
@{ Name = 'internal issue reference'; Pattern = 'evo\.scripts#\d+' }
@{ Name = 'private product domain'; Pattern = '\b(smartplantehs\.com|provensheet\.com|evoehs\.com|civilcode\.evomedia\.net|dashboard\.evomedia\.net|webmail\.evomedia\.net|mail-admin\.evomedia\.net|docketmail\.evomedia\.net|cardiff\.evomedia\.net|platform\.evomedia\.net|ai\.evomedia\.net|git\.evomedia\.net|analytics\.evomedia\.net)\b' }
@{ Name = 'private-only script'; Pattern = '\b(register_civilcode|register_docketmail|sp_seed_demo_prod|zpublish_stats|zcoverage|zresume|swag_set_owner|provision_demo|apply_platform_config_fixes)\b' }
@{ Name = 'local drive path'; Pattern = '[A-Za-z]:\\\\?evomedia\.net' }
@{ Name = 'operator home path'; Pattern = '/home/ubuntu/' }
@{ Name = 'real pem key name'; Pattern = 'evomedia-prod\.pem' }
# RFC 5737 reserves 203.0.113.0/24 for documentation - that one is the
# correct placeholder and must stay allowed, as are loopback and the
# private ranges. Anything else that looks like a public IPv4 literal is
# suspect.
#
# The boundaries are [\d.] rather than \d on purpose: this toolkit's own
# 5-segment version (v1.0.0.0.14) contains "0.0.0.14", which a plain
# digit boundary happily reads as an address. Refusing a match that
# touches another dot rules out every version string without weakening
# detection of a real address, which is always delimited by whitespace
# or quotes.
@{ Name = 'non-documentation IP'; Pattern = '(?<![\d.])(?!203\.0\.113\.)(?!127\.0\.0\.1)(?!0\.0\.0\.0)(?!255\.)(?!10\.)(?!192\.168\.)(?!172\.(1[6-9]|2\d|3[01])\.)\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}(?![\d.])' }
)
}