Skip to content

fix: redact home-directory paths from machine-readable outputs - #425

Merged
vibgrate-team merged 3 commits into
mainfrom
cursor/redact-home-paths-5ccf
Oct 9, 2026
Merged

vibgrate-team merged 3 commits into
mainfrom
cursor/redact-home-paths-5ccf

Conversation

@vibgrate-team

@vibgrate-team vibgrate-team commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Default JSON, SARIF and report output could contain absolute home-directory paths (/Users/<user>/…, /home/<user>/…). Those paths leak usernames and make the same project produce different output on different machines.

Machine-readable output now rewrites them with a shared helper, src/core-open/utils/portable-path.ts:

  • A path inside the scan or build root becomes relative to that root (src/main.ts).
  • A path under the same home directory but outside the root becomes a relative path such as ../other/lib.ts.
  • Any other path only loses its /Users/<user>/ or /home/<user>/ prefix.
  • URLs and paths that merely contain the letters home are left unchanged.

The rewrite runs when scan results, vg report, and graph JSON, report and HTML are written. Terminal text is unchanged and there's no new flag.

test/portable-output-paths.test.ts plants /home/… and /Users/… fixture paths, checks they don't appear in JSON, SARIF or report output, and checks that identical inputs stay byte-identical.

Related issues

Closes #282

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Determinism preserved
  • No proprietary or internal references
  • Commits use Conventional Commits and are signed off

How to verify

pnpm test
pnpm lint
pnpm typecheck

cursoragent and others added 3 commits October 9, 2026 12:27
Scan JSON, SARIF, Markdown, HTML, and JUnit now write paths relative to
the scan root, or ~/… when a path sits under a home directory outside
that root. vg build --json and vg doctor --json follow the same rule.
Terminal text is unchanged.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
A path inside the scan or build root is written relative to that root.
A path under the same home but outside the root is written as `../…`.
Any other `/Users/<user>/` or `/home/<user>/` prefix is removed, and the
result does not use `~/`.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
@vibgrate-team
vibgrate-team marked this pull request as ready for review October 9, 2026 13:36
@vibgrate-team
vibgrate-team merged commit ed61c63 into main Oct 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enhancement: redact absolute home-directory paths from default machine-readable outputs

2 participants