Skip to content

fix(coding-plans): suppress credential fingerprint false positive#3846

Merged
RSO merged 1 commit into
mainfrom
fix/codeql-440-coding-plan-fingerprint
Jun 9, 2026
Merged

fix(coding-plans): suppress credential fingerprint false positive#3846
RSO merged 1 commit into
mainfrom
fix/codeql-440-coding-plan-fingerprint

Conversation

@kilo-code-bot

@kilo-code-bot kilo-code-bot Bot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Suppress CodeQL alert 440 for the coding-plan credential fingerprint HMAC.
  • Document that the HMAC is a keyed duplicate-detection fingerprint for managed API keys, not password storage.

Verification

N/A - no manual user-facing flow applies to this code-scanning suppression.

Visual Changes

N/A

Reviewer Notes

@kilo-code-bot kilo-code-bot Bot requested a review from RSO June 9, 2026 09:35
@RSO RSO merged commit 3cff0fb into main Jun 9, 2026
16 checks passed
@RSO RSO deleted the fix/codeql-440-coding-plan-fingerprint branch June 9, 2026 12:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants