Skip to content

fix(secrets): reject a --diff ref that starts with "-" - #267

Merged
Rome-1 merged 1 commit into
mainfrom
mayor-agent/diff-ref-option-guard
Oct 2, 2026
Merged

Rome-1 merged 1 commit into
mainfrom
mayor-agent/diff-ref-option-guard

Conversation

@Rome-1

@Rome-1 Rome-1 commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Summary

rafter secrets --diff <ref> (and the deprecated rafter agent scan --diff) passes the ref to git diff as a positional argument.
git treats any argument starting with - as one of its own options, so the value was not always used as a ref.

Both CLIs now reject a --diff value that starts with - before running git, printing Error: invalid ref "<value>" (a git ref cannot start with "-") and exiting 2, the documented "invalid ref" code for rafter secrets.
No valid git ref starts with -, so normal use is unaffected.

Tests

  • node/tests/secret-scanning-e2e.test.ts: "rejects a --diff ref that git would parse as an option"
  • python/tests/test_secret_scanning_e2e.py: test_rejects_a_diff_ref_that_git_would_parse_as_an_option

Each runs the CLI against a temporary git repo with an option-shaped --diff value and asserts exit 2 and that the file it names is left untouched.
Both fail on main and pass on this branch.

tsc clean. Python suite: 1754 passed, 1 skipped. Node suite: 2275 passed; the 3 Cursor hook tests that fail also fail on main in a local checkout and are unrelated.

The --diff value is passed to `git diff` as a positional argument, and
git parses anything starting with "-" as one of its own options. Reject
such a value with exit 2 (invalid ref) before running git, in both the
Node and Python CLIs, for `rafter secrets` and `rafter agent scan`.

Each runtime gets an end-to-end test that passes an option-shaped ref
and asserts exit 2 with the target file left untouched.
@Rome-1
Rome-1 merged commit 9366bfb into main Oct 2, 2026
10 checks passed
@Rome-1
Rome-1 deleted the mayor-agent/diff-ref-option-guard branch October 2, 2026 04:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant