{"record":{"id":"be9cb218de1b3a92","repo":"santifer/career-ops","slug":"possible-personal-data-in-file-pattern","errorCode":null,"errorMessage":"Possible personal data in ${file}: \"${pattern}\"","messagePattern":"Possible personal data in (.+?): \"(.+?)\"","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"test-all.mjs","lineNumber":2017,"sourceCode":"// gitignored files can't trigger false positives because they were never\n// going to reach a commit anyway.\n// Argument vector for git grep — no shell involved, so the pathspecs and\n// pattern reach git verbatim (no quoting layer, nothing interpolated).\nconst grepPathspecs = scanExtensions.map(e => `*.${e}`);\n\nlet leakFound = false;\nfor (const pattern of leakPatterns) {\n  const result = run(\n    'git',\n    ['grep', '-n', pattern, '--', ...grepPathspecs],\n    { stdio: ['pipe', 'pipe', 'ignore'] }\n  );\n  if (result) {\n    for (const line of result.split('\\n')) {\n      const file = line.split(':')[0];\n      if (allowedFiles.some(a => file.includes(a))) continue;\n      if (file.includes('dashboard/go.mod')) continue;\n      warn(`Possible personal data in ${file}: \"${pattern}\"`);\n      leakFound = true;\n    }\n  }\n}\nif (!leakFound) {\n  pass('No personal data leaks outside allowed files');\n}\n\n// ── 7. ABSOLUTE PATH CHECK ──────────────────────────────────────\n\nconsole.log('\\n7. Absolute path check');\n\n// Same git grep approach: only scans tracked files. Untracked AI tool\n// outputs, local debate artifacts, etc. can't false-positive here.\nconst absPathRaw = run(\n  'git',\n  ['grep', '-n', '/Users/', '--', '*.mjs', '*.sh', '*.md', '*.go', '*.yml'],\n  { stdio: ['pipe', 'pipe', 'ignore'] }","sourceCodeStart":1999,"sourceCodeEnd":2035,"githubUrl":"https://github.com/santifer/career-ops/blob/aac998c7ed7248ea853b720ceeb1fdbeb322fc5d/test-all.mjs#L1999-L2035","documentation":"test-all.mjs scans repository files for patterns that look like personal data (emails, phone numbers, etc. from a user's CV or tracker). When a pattern matches in a file not on the allowedFiles allowlist, it warns naming the file and the matched pattern, and sets leakFound so the 'no leaks' pass message is not printed. This protects users from committing private job-search data.","triggerScenarios":"A grep-like result line's file path is not in allowedFiles and not dashboard/go.mod, and its content matches a personal-data pattern — e.g. the user's real cv.md, an exported tracker, or a report containing a recruiter's email address.","commonSituations":"Committing a real CV into a repo cloned from the public template, pasting real recruiter correspondence into reports/, adding new generated files (digests, prep notes) that were never added to allowedFiles, or moving data files to a new path the allowlist does not cover.","solutions":["Open the flagged file and remove/scrub the personal data, or move it to a gitignored location (output/, documents/ are gitignored).","If the file is legitimately allowed (e.g. a new template or fixture), add its path to allowedFiles in the personal-data check in test-all.mjs.","Check git status: if the file should never be tracked, add it to .gitignore and untrack it (git rm --cached).","If the pattern is a false positive (e.g. an example@ email in a fixture), refine the pattern rather than the allowlist."],"exampleFix":"// before (test-all.mjs allowedFiles)\nconst allowedFiles = ['config/profile.example.yml', 'cv.example.md'];\n// after\nconst allowedFiles = ['config/profile.example.yml', 'cv.example.md', 'templates/my-new-fixture.md'];","handlingStrategy":"validation","validationCode":"const hits = execSync(`grep -RInE '${pattern}' . || true`, 'utf8').split('\\n').map(l => l.split(':')[0]).filter(f => !allowedFiles.some(a => f.includes(a)) && !f.includes('dashboard/go.mod')); if (hits.length) console.warn('scrub personal data from:', hits);","typeGuard":"const isAllowed = (file) => allowedFiles.some(a => file.includes(a)) || file.includes('dashboard/go.mod');","tryCatchPattern":"// avoid writing real personal data at all; run the scan before commit\ngit diff --name-only | grep -E '^(cv|data|reports)' && node check-personal-data.mjs","preventionTips":["Keep real CV/tracker data in gitignored paths only","Use the example templates (cv.example.md, config/profile.example.yml) in any public repo","Extend allowedFiles whenever you add a new generated-file location","Run the personal-data check as a pre-commit hook"],"tags":["privacy","personal-data","git-hygiene","test-runner"],"backgroundTag":"personal-data-leak","analyzedSha":"aac998c7ed7248ea853b720ceeb1fdbeb322fc5d","analyzedAt":"2026-09-16T06:35:29.214Z","contentChangedAt":"2026-09-16T06:35:29.214Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}