Skip to content

ci: add scan config to redteam targets#50

Closed
cdot65 wants to merge 4 commits into
mainfrom
cdot65/redteam-scan-config
Closed

ci: add scan config to redteam targets#50
cdot65 wants to merge 4 commits into
mainfrom
cdot65/redteam-scan-config

Conversation

@cdot65

@cdot65 cdot65 commented Apr 15, 2026

Copy link
Copy Markdown
Owner

Summary

  • Add scan details (id, name, status) to litellm-openai-chatgpt-5.4-mini-airs.yaml
  • Update workflow to read scan config from YAML files instead of hardcoding STATIC

Test plan

  • Verify the AI Red Team Scan workflow triggers on this PR
  • Confirm scan config is read from the YAML file

🤖 Generated with Claude Code

cdot65 and others added 4 commits April 15, 2026 08:15
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@cdot65

cdot65 commented May 28, 2026

Copy link
Copy Markdown
Owner Author

Superseded by #233 — rebased onto main and bundled with #77 + #112.

@cdot65 cdot65 closed this May 28, 2026
cdot65 added a commit that referenced this pull request May 28, 2026
#112 redteam report DYNAMIC fix (#233)

* test(redteam): RED for getDynamicReport service + renderer (#112)

* fix(redteam): route DYNAMIC jobs to getDynamicReport (#112)

Previously redteam report fell through to getStaticReport for any
non-CUSTOM jobType, including DYNAMIC, which 500s on the static
endpoint. Add a RedTeamDynamicReport type, getDynamicReport service
method, renderDynamicReport renderer, and the DYNAMIC routing branch.

* ci(redteam): rebase scan workflow with CUSTOM prompt sets + ASR gate (#50)

Adds scan_config to the litellm target, switches the redteam-scan
workflow to CUSTOM scans with prompt sets, skips targets without a
scan_config, and adds an ASR-threshold gate plus a step-summary block
of scan results.

Resolves a env-block conflict with the Node 24 bump (#76) by merging
both env keys.

* feat(dlp): add visible-text embedding techniques for PDF/PNG/JPEG/SVG/DOCX

Adds 6 new dirty-file generators (5 formats × 1-2 techniques each):
- PDF: visible, visible-samecolor
- PNG: visible (text overlay)
- JPEG: visible (text overlay)
- SVG: visible (rendered text node)
- DOCX: visible, visible-samecolor

visible-samecolor renders body text in the same color as background — present
and OCR-extractable but camouflaged from the eye. Useful for testing scanner
robustness vs. simple visual review.

Corpus jumps from 15 → 21 dirty files per full run.

* test(dlp): cover visible + visible-samecolor embedders

Per-format embed specs add visible-text assertions; orchestrate spec dirty
count 15 → 21.

* docs(dlp): document visible + visible-samecolor techniques on runtime dlp generate

Retargets onto the post-v2.11.0 command (was runtime dlp-gen). Updates AGENTS,
SKILL.md, generate.md, and full-cli-sweep corpus counts (15 → 21 dirty).

* chore: changesets for bundled dlp visible-text + redteam CI + report dynamic

* style: biome single-line formatting fix

* docs: regenerate typedoc api ref for new RedTeamDynamicReport types
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant