fix(secrets): reject a --diff ref that starts with "-" - #267
Merged
Merged
Conversation
The --diff value is passed to `git diff` as a positional argument, and git parses anything starting with "-" as one of its own options. Reject such a value with exit 2 (invalid ref) before running git, in both the Node and Python CLIs, for `rafter secrets` and `rafter agent scan`. Each runtime gets an end-to-end test that passes an option-shaped ref and asserts exit 2 with the target file left untouched.
This was referenced Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
rafter secrets --diff <ref>(and the deprecatedrafter agent scan --diff) passes the ref togit diffas a positional argument.git treats any argument starting with
-as one of its own options, so the value was not always used as a ref.Both CLIs now reject a
--diffvalue that starts with-before running git, printingError: invalid ref "<value>" (a git ref cannot start with "-")and exiting2, the documented "invalid ref" code forrafter secrets.No valid git ref starts with
-, so normal use is unaffected.Tests
node/tests/secret-scanning-e2e.test.ts: "rejects a --diff ref that git would parse as an option"python/tests/test_secret_scanning_e2e.py:test_rejects_a_diff_ref_that_git_would_parse_as_an_optionEach runs the CLI against a temporary git repo with an option-shaped
--diffvalue and asserts exit2and that the file it names is left untouched.Both fail on
mainand pass on this branch.tscclean. Python suite: 1754 passed, 1 skipped. Node suite: 2275 passed; the 3 Cursor hook tests that fail also fail onmainin a local checkout and are unrelated.