Repository navigation
Fencier v0.1 release candidate + audit.include_patch fix - #1
Merged
Merged
Conversation
The audit.include_patch policy flag was validated by the schema,
shipped in the default fencier.yaml, and documented in the README,
but no code ever read it. Setting it to true had no effect: patches
were never written under any configuration.
collectGitDiff already ran `git diff` and discarded the patch text
after extracting added lines. It now returns { files, patch } and
takes an includePatch option, re-reading the diff with default
context so the stored patch is reviewable (the scan patch uses
--unified=0 and has no context lines). The extra git call only runs
when audits are actually being written.
writeAuditReports gates the patch on policy.audit.include_patch in
one place, then emits it as a ```diff section in Markdown and a
patch key in JSON.
The patch is the only unmasked part of an audit, so a diff that adds
a secret now stores it in .fencier/audits/ in plaintext when the flag
is on. Documented in the README security section, docs/security.md,
and inline in the generated report. The default stays false.
Also documents three commands missing from the README reference:
codex install, codex fix-audit brief, and codex skill path.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Brings the v0.1 release candidate to
mainand fixes a documented-but-dead policy flag found while auditing the README against the actual implementation.Two commits, reviewable independently:
093b307— v0.1 release candidate: standalone CLI bundling, realdoctordiagnostics, secret-safe--jsonoutput, andscripts/release-check.mjsinstall-from-tarball validation.438d878— makesaudit.include_patchactually work, plus doc corrections.The
include_patchbugaudit.include_patchwas validated by the schema, shipped in the defaultfencier.yaml, documented in the README policy example, and asserted in a test — but no code ever read it. Setting it totruedid nothing; patches were never written under any configuration.The plumbing was almost there:
collectGitDiffalready rangit diffand threw the patch away after extracting added lines.git.ts—collectGitDiffreturns{ files, patch }and takes anincludePatchoption. The--unified=0scan patch is kept for secret detection; a second diff with default context runs only when a reviewable patch is requested, and only when audits are actually being written (--no-auditskips it).audit.ts— the flag is enforced in one place (createAuditEvent), then rendered as a ```diff section in Markdown and apatchkey in JSON.cli.ts— threads the patch through.Security note for reviewers
The patch is the only unmasked part of an audit. With
include_patch: true, a diff that adds a secret writes it to.fencier/audits/in plaintext. Every other audit field stays masked,--jsonverify output is unchanged, and the default remainsfalse. The tradeoff is documented in the README security section,docs/security.md, and inline in the generated report.Docs
Added three commands missing from the README reference:
codex install,codex fix-audit brief,codex skill path.Testing
pnpm run cigreen — lint, typecheck, 51 tests (up from 48), build.pnpm release:checkpasses — packs, installs from tarball, exercises doctor / init / skills / PASS / FAIL.include_patch: truewrites it to both formats.fencier verifyon this change reports PASS / LOW.New coverage:
git.tsreturns patch text only when asked, and audits omit/include the patch per the policy flag in both formats.