@@ -68,15 +68,48 @@ def _infer_file_type(path: str) -> str:
6868 return FILE_TYPES .get (suffix , "other" )
6969
7070
71- _BINARY_EXTENSIONS = frozenset ({
72- ".pdf" , ".png" , ".jpg" , ".jpeg" , ".gif" , ".bmp" , ".ico" ,
73- ".woff" , ".woff2" , ".ttf" , ".otf" , ".eot" ,
74- ".zip" , ".tar" , ".gz" , ".bz2" , ".xz" , ".7z" , ".rar" ,
75- ".exe" , ".dll" , ".so" , ".dylib" , ".bin" , ".o" , ".a" ,
76- ".pyc" , ".pyo" , ".class" , ".wasm" ,
77- ".mp3" , ".mp4" , ".wav" , ".avi" , ".mov" , ".webm" ,
78- ".sqlite" , ".db" ,
79- })
71+ _BINARY_EXTENSIONS = frozenset (
72+ {
73+ ".pdf" ,
74+ ".png" ,
75+ ".jpg" ,
76+ ".jpeg" ,
77+ ".gif" ,
78+ ".bmp" ,
79+ ".ico" ,
80+ ".woff" ,
81+ ".woff2" ,
82+ ".ttf" ,
83+ ".otf" ,
84+ ".eot" ,
85+ ".zip" ,
86+ ".tar" ,
87+ ".gz" ,
88+ ".bz2" ,
89+ ".xz" ,
90+ ".7z" ,
91+ ".rar" ,
92+ ".exe" ,
93+ ".dll" ,
94+ ".so" ,
95+ ".dylib" ,
96+ ".bin" ,
97+ ".o" ,
98+ ".a" ,
99+ ".pyc" ,
100+ ".pyo" ,
101+ ".class" ,
102+ ".wasm" ,
103+ ".mp3" ,
104+ ".mp4" ,
105+ ".wav" ,
106+ ".avi" ,
107+ ".mov" ,
108+ ".webm" ,
109+ ".sqlite" ,
110+ ".db" ,
111+ }
112+ )
80113
81114_NULL_BYTE_SAMPLE_SIZE = 512
82115
@@ -95,7 +128,9 @@ def _is_binary_file(path: str, content: str) -> bool:
95128)
96129
97130
98- def _is_env_file_reference_in_docs (finding : AnalyzerFinding , file_type : str , file_path : str = "" ) -> bool :
131+ def _is_env_file_reference_in_docs (
132+ finding : AnalyzerFinding , file_type : str , file_path : str = ""
133+ ) -> bool :
99134 """Return True if a PE3 finding is a documentation reference to .env files, not actual access.
100135
101136 SKILL.md is exempt: it is the agent's primary instruction file, so `.env`
@@ -230,7 +265,9 @@ def run_static_patterns(
230265 if _is_env_file_reference_in_docs (af , file_type , path ):
231266 logger .debug (
232267 "Filtered PE3 .env doc reference: %s in %s:%d" ,
233- af .rule_id , path , af .location .start_line ,
268+ af .rule_id ,
269+ path ,
270+ af .location .start_line ,
234271 )
235272 continue
236273 if af .context and is_code_example (af .context ):
0 commit comments