santifer/career-ops · warning
Possible personal data in
Error message
Possible personal data in ${file}: "${pattern}" What it means
test-all.mjs scans repository files for patterns that look like personal data (emails, phone numbers, etc. from a user's CV or tracker). When a pattern matches in a file not on the allowedFiles allowlist, it warns naming the file and the matched pattern, and sets leakFound so the 'no leaks' pass message is not printed. This protects users from committing private job-search data.
Solutions
- Open the flagged file and remove/scrub the personal data, or move it to a gitignored location (output/, documents/ are gitignored).
- If the file is legitimately allowed (e.g. a new template or fixture), add its path to allowedFiles in the personal-data check in test-all.mjs.
- Check git status: if the file should never be tracked, add it to .gitignore and untrack it (git rm --cached).
- If the pattern is a false positive (e.g. an example@ email in a fixture), refine the pattern rather than the allowlist.
Example fix
// before (test-all.mjs allowedFiles) const allowedFiles = ['config/profile.example.yml', 'cv.example.md']; // after const allowedFiles = ['config/profile.example.yml', 'cv.example.md', 'templates/my-new-fixture.md'];
Defensive patterns
Strategy: validation
Validate before calling
const hits = execSync(`grep -RInE '${pattern}' . || true`, 'utf8').split('\n').map(l => l.split(':')[0]).filter(f => !allowedFiles.some(a => f.includes(a)) && !f.includes('dashboard/go.mod')); if (hits.length) console.warn('scrub personal data from:', hits); Type guard
const isAllowed = (file) => allowedFiles.some(a => file.includes(a)) || file.includes('dashboard/go.mod'); Try / catch
// avoid writing real personal data at all; run the scan before commit git diff --name-only | grep -E '^(cv|data|reports)' && node check-personal-data.mjs
Prevention
- Keep real CV/tracker data in gitignored paths only
- Use the example templates (cv.example.md, config/profile.example.yml) in any public repo
- Extend allowedFiles whenever you add a new generated-file location
- Run the personal-data check as a pre-commit hook
When it happens
Trigger: A grep-like result line's file path is not in allowedFiles and not dashboard/go.mod, and its content matches a personal-data pattern — e.g. the user's real cv.md, an exported tracker, or a report containing a recruiter's email address.
Common situations: Committing a real CV into a repo cloned from the public template, pasting real recruiter correspondence into reports/, adding new generated files (digests, prep notes) that were never added to allowedFiles, or moving data files to a new path the allowlist does not cover.
Related errors
- archive render skipped — no Playwright browser in env
- Cannot import generate-pdf.mjs
- concurrent reservation test flaked
- merge-tracker concurrent write test flaked
- used s of its s budget ( %) — it is passing, but it is…
AI-assisted analysis of santifer/career-ops@aac998c7ed (2026-09-16).
Data as JSON: /api/errors/be9cb218de1b3a92.
Report an issue: GitHub.
Appendix: source
Thrown at test-all.mjs:2017
// gitignored files can't trigger false positives because they were never
// going to reach a commit anyway.
// Argument vector for git grep — no shell involved, so the pathspecs and
// pattern reach git verbatim (no quoting layer, nothing interpolated).
const grepPathspecs = scanExtensions.map(e => `*.${e}`);
let leakFound = false;
for (const pattern of leakPatterns) {
const result = run(
'git',
['grep', '-n', pattern, '--', ...grepPathspecs],
{ stdio: ['pipe', 'pipe', 'ignore'] }
);
if (result) {
for (const line of result.split('\n')) {
const file = line.split(':')[0];
if (allowedFiles.some(a => file.includes(a))) continue;
if (file.includes('dashboard/go.mod')) continue;
warn(`Possible personal data in ${file}: "${pattern}"`);
leakFound = true;
}
}
}
if (!leakFound) {
pass('No personal data leaks outside allowed files');
}
// ── 7. ABSOLUTE PATH CHECK ──────────────────────────────────────
console.log('\n7. Absolute path check');
// Same git grep approach: only scans tracked files. Untracked AI tool
// outputs, local debate artifacts, etc. can't false-positive here.
const absPathRaw = run(
'git',
['grep', '-n', '/Users/', '--', '*.mjs', '*.sh', '*.md', '*.go', '*.yml'],
{ stdio: ['pipe', 'pipe', 'ignore'] }View on GitHub (pinned to aac998c7ed)