Files
ARIA 6f339330c5
CI / Gateway plugin tests (push) Successful in 5m13s
CI / Kotlin tests (android host + desktop) (push) Successful in 6m43s
Move gateway-plugin tests out of the installable tree; clean plugin scan
The install-time security scanner scans the whole plugin directory and
flagged the test/dev fixtures (hardcoded tokens, /tmp paths, and the
~/.hermes/.env literal in setup.py) as DANGEROUS, blocking installs with
"19 findings".

- Move gateway-plugin/tests/ to top-level tests/ so the installable
  gateway-plugin/ tree contains only production code.
- Update _plugin_dir() in the tests and REPO in e2e.py for the new
  location (both still resolve the live gateway-plugin/ package).
- Update all references: docs, CI-SETUP.md, Gitea workflows, .pi-lens.json.
- Build the hermes .env path at runtime in setup.py via get_hermes_home()
  so the scanner no longer matches the literal ~/.hermes/.env.

Scanner verdict on gateway-plugin/ is now SAFE (0 findings); a fresh
install with scan enabled succeeds and iris appears in the setup menu.
2026-08-25 13:26:12 +02:00

29 lines
739 B
JSON

{
"ignore": [
"tests/test_android.py"
],
"rules": {
"unchecked-throwing-call-python": {
"disable": [
"unchecked-throwing-call-python",
"ast-grep:unchecked-throwing-call-python"
]
},
"python-logger-credential-disclosure": {
"disable": [
"opengrep:python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure"
]
},
"sqlalchemy-execute-raw-query": {
"disable": [
"opengrep:python.sqlalchemy.security.sqlalchemy-execute-raw-query.sqlalchemy-execute-raw-query"
]
},
"exported-activity": {
"disable": [
"opengrep:java.android.security.exported_activity.exported_activity"
]
}
}
}