chore(repo): warn on private-product vocabulary - #77
Merged
Merged
Conversation
The private-terms check matched names only, so two worked examples lifted from a private product shipped without naming it. Overlay lines prefixed `warn:` now flag that product's domain vocabulary as a PR annotation, file and line only, without failing the build: some of those words are ordinary English. The privacy-audit skill used the same product's data categories as examples; it now uses generic ones. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FqTSev7LyLprLNwPfVfQA8
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The private-terms check only matched names, so worked examples lifted from a private product (fixed in #75) shipped without naming it.
warn:are now warnings: each hit becomes a::warningannotation on the PR with file and line only (never the term or text, since CI logs are public). Locally the matching line prints. Warnings never fail the build and never run againstdocs/.privacy-auditused that product's data categories as examples; now generic.The vocabulary itself lives only in the gitignored local list and the
PRIVATE_TERMSsecret; nothing in this PR reveals it.Tested locally: clean tree passes with 0 warnings; a planted line warns (exit 0) and emits the annotation under
GITHUB_ACTIONS=true.🤖 Generated with Claude Code
https://claude.ai/code/session_01FqTSev7LyLprLNwPfVfQA8