Skip to content

fix: freeze.txt の URL から認証情報を除く - #1935

Merged
ivis-miyachi merged 1 commit into
develop_v2.1.0from
fix/remove-credential-freeze-txt
Oct 5, 2026
Merged

ivis-miyachi merged 1 commit into
develop_v2.1.0from
fix/remove-credential-freeze-txt

Conversation

@mhaya

@mhaya mhaya commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

概要 (Summary)

freeze.txt の -e git+https://... 行(43 行)に、取得時のユーザ名とアクセストークンが URL に埋め込まれたまま残っていたため除去する。
RCOSDP/weko は public なので、URL から認証情報を外しても取得できる。

変更タイプ (Type of Change)

  • 🔒 セキュリティ修正 (Security Fix)

補足

  • 該当トークンは失効済み(2026-10-04)。過去の履歴に残る値は無効になっている。
  • freeze.txt はコード・スクリプトから参照されていない。

動作確認

  • grep -c ghp_ freeze.txt → 0
  • 差分は URL の user:token@ 部分のみ(43 行)

🤖 Generated with Claude Code

pip freeze の出力に、取得時に使ったユーザ名とアクセストークンが
URL に埋め込まれたまま残っていた。RCOSDP/weko は public なので
認証なしで取得でき、認証情報は不要。

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sourcery-ai

sourcery-ai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

freeze.txt の Git 依存 URL 43 行からユーザー名とアクセストークンを除去し、公開リポジトリを認証なしで取得する形式に修正したセキュリティ対応。

File-Level Changes

Change Details Files
freeze.txt に記録された Git URL から埋め込み認証情報を除去する。
  • 43 行の user:token@ 部分を削除し、公開リポジトリの未認証 URL に変更
  • 認証トークンがファイル内に残っていないことを確認
freeze.txt

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@coderabbitai

coderabbitai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 274d9285-7930-4fd8-9f3b-5bcb6de9c3a3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Fixed security issues:


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

API インベントリ差分(件数のみ)

台帳ブランチ: develop_v2.1.0

明細は公開できないため件数のみ表示しています。該当箇所はプライベートリポジトリ側の台帳・レポートで確認してください。

ベースラインとの差分

API インベントリ差分レポート

  • 旧: b572c442d v2.0.4-577-gb572c442d (profile=default) endpoints=933 (外部ライブラリ由来 359)
  • 新: 00b36e3b9 v2.0.4-660-g00b36e3b9 (profile=default) endpoints=933 (外部ライブラリ由来 359)

判定: ❌ FAIL (FAIL 1 / WARN 2)

サマリ

分類 件数
ADDED 0
REMOVED 0
RULE_CHANGED 0
METHODS_CHANGED 0
AUTH_CHANGED 36
IMPL_CHANGED 8
ATTRS_UNKNOWN_NEW 0
ModelView 追加 0
ModelView 削除 0
ModelView フラグ変化 0
config 変化 2
コメントアウト認証の増加 0
依存パッケージの版変化 0

[FAIL] G2 認証系デコレータが削除された — 3件

件数のみ。該当の経路名はプライベートリポジトリ側の完全版レポートを参照。

[WARN] W2 実装本体が変化(data_op / 情報露出を再確認) — 8件

件数のみ。該当の経路名はプライベートリポジトリ側の完全版レポートを参照。

[WARN] W5 監視対象 config が変化した — 2件

件数のみ。該当の経路名はプライベートリポジトリ側の完全版レポートを参照。


台帳との突き合わせ

(生成されませんでした)

ソース由来の経路検知

(生成されませんでした)

@ivis-miyachi
ivis-miyachi merged commit 6743f9a into develop_v2.1.0 Oct 5, 2026
147 of 159 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants