From d2f222443e6f6644ef1ebf4ec6572a3d5f9f0708 Mon Sep 17 00:00:00 2001 From: Christopher Kevin Date: Mon, 5 Oct 2026 22:20:19 -0700 Subject: [PATCH] test: clear two test-only CodeQL alerts py/incomplete-url-substring-sanitization in test_provider_config.py: the no-credential test checked that "build.nvidia.com" appeared somewhere in the setup message. It now checks the exact " Get a key: https://build.nvidia.com" line, which is stricter. py/clear-text-storage-sensitive-data in test_harbor_local_sandbox.py: the bwrap host-home test wrote a value named `secret` to a file in the host home. The test only needs recognizable text to prove the sandbox cannot read that file, so the value is now a plain marker. Co-Authored-By: Claude Opus 5.5 Signed-off-by: Christopher Kevin --- tests/test_harbor_local_sandbox.py | 9 +++++---- tests/test_provider_config.py | 2 +- 2 files changed, 6 insertions(+), 5 deletions(-) diff --git a/tests/test_harbor_local_sandbox.py b/tests/test_harbor_local_sandbox.py index 560a294b..71f3e714 100644 --- a/tests/test_harbor_local_sandbox.py +++ b/tests/test_harbor_local_sandbox.py @@ -1469,8 +1469,9 @@ def test_runtime_visible_read_only_without_unrelated_host_home_contents(self, ru probe_dir = Path(tempfile.mkdtemp(prefix=".skilleval-host-read-probe-", dir=Path.home())).resolve() sentinel = probe_dir / "sentinel.txt" - secret = "BWRAP-HOST-HOME-SECRET" - sentinel.write_text(secret, encoding="utf-8") + # A plain marker, not a credential: the test only needs text it can look for. + marker = "BWRAP-HOST-HOME-MARKER" + sentinel.write_text(marker, encoding="utf-8") python_executable = Path(sys.executable).resolve() runtime_root = python_executable.parent.parent runtime_write_probe = runtime_root / f".skillevaluator-write-probe-{probe_dir.name}" @@ -1500,8 +1501,8 @@ def test_runtime_visible_read_only_without_unrelated_host_home_contents(self, ru try: result = self._run([str(python_executable), "-B", "-c", code], run_root) assert result.returncode == 0, result.stderr - assert secret not in result.stdout - assert secret not in result.stderr + assert marker not in result.stdout + assert marker not in result.stderr finally: runtime_write_probe.unlink(missing_ok=True) shutil.rmtree(probe_dir, ignore_errors=True) diff --git a/tests/test_provider_config.py b/tests/test_provider_config.py index b32a0c08..780fd057 100644 --- a/tests/test_provider_config.py +++ b/tests/test_provider_config.py @@ -468,7 +468,7 @@ def test_no_credential_llm_error_leads_with_copyable_setup() -> None: assert message.startswith("No provider is configured.\n\n") assert " export SKILL_EVAL_LLM_PROVIDER=nv_build\n" in message assert " export NVIDIA_API_KEY='your-api-key'\n" in message - assert "build.nvidia.com" in message + assert " Get a key: https://build.nvidia.com" in message.splitlines() assert "OPENAI_API_KEY" in message assert "ANTHROPIC_API_KEY" in message assert "https://docs.nvidia.com/skills/skillevaluator/configuration" in message