Skip to content

fix(core): stop masking pnpm store paths as email addresses - #817

Merged
HugoRCD merged 2 commits into
mainfrom
EVL-533/fix-email-redaction-pnpm-paths
Oct 10, 2026
Merged

HugoRCD merged 2 commits into
mainfrom
EVL-533/fix-email-redaction-pnpm-paths

Conversation

@evlogai

@evlogai evlogai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Closes #813. Linear: EVL-533.

What changed

The built-in email pattern accepted digits and dots in the top-level domain, so name@version segments in pnpm store paths matched as addresses. Stack traces lost the package name and version. The pattern now requires a letters-only TLD of two or more characters. Subdomains still match, and real addresses are masked as before.

Before / after

Real redactEvent output with built-in email redaction:

- file:///app/node_modules/.pnpm/h***@***.11/node_modules/h3/dist/index.mjs:2007:9
+ file:///app/node_modules/.pnpm/h3@1.15.11/node_modules/h3/dist/index.mjs:2007:9

- node_modules/.pnpm/u***@***.0/node_modules/unctx/dist/index.mjs
+ node_modules/.pnpm/unctx@2.5.0/node_modules/unctx/dist/index.mjs

  alice@example.com -> a***@***.com   (unchanged)

Verification

  • Regression test added in its own commit (test(core): ...). It failed on main with the masked output above, and passes with the fix.
  • pnpm run lint, pnpm run typecheck, pnpm run test: all exit 0 in the sandbox (evlog: 100 files, 2038 tests passed). Cold checks, read-only Turbo remote cache.
  • Not run: pnpm test:coverage and pnpm api:snapshot (no public export changed).
  • No rendered surface, so no capture.

Known edge

An internationalized TLD such as xn--p1ai is not matched in full. Its local part is still masked, but the domain tail stays visible. Real addresses with IDN domains are rare, and the previous pattern did not handle them correctly either.

Changeset

patch for evlog.

ELI5

The email hider was mistaking version numbers in file paths for email addresses, so error reports lost part of the path. The fix only treats something as an email when the ending looks like a real domain ending such as .com. Real email addresses are hidden as before.

@evlogai
evlogai Bot requested a review from HugoRCD October 10, 2026 18:36
@vercel

vercel Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
evi Building Building Preview Oct 10, 2026 6:37pm UTC
evlog-docs Ready Ready Preview, v0 Oct 10, 2026 6:37pm UTC
evlog-render-lab Ready Ready Preview Oct 10, 2026 6:37pm UTC
evlog-telemetry Building Building Preview Oct 10, 2026 6:37pm UTC
just-use-evlog Ready Ready Preview Oct 10, 2026 6:37pm UTC

Request Review

@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 5c05129f-80c6-4aea-a9a4-5da008e94d4b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the bug Something isn't working label Oct 10, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thank you for following the naming conventions! 🙏

@pkg-pr-new

pkg-pr-new Bot commented Oct 10, 2026

Copy link
Copy Markdown
@evlog/cli

npm i https://pkg.pr.new/@evlog/cli@817

evlog

npm i https://pkg.pr.new/evlog@817

@evlog/nuxthub

npm i https://pkg.pr.new/@evlog/nuxthub@817

@evlog/signals

npm i https://pkg.pr.new/@evlog/signals@817

@evlog/telemetry

npm i https://pkg.pr.new/@evlog/telemetry@817

commit: 3c82ff0

@HugoRCD
HugoRCD merged commit 038de6a into main Oct 10, 2026
17 of 19 checks passed
@HugoRCD
HugoRCD deleted the EVL-533/fix-email-redaction-pnpm-paths branch October 10, 2026 18:37

This branch was successfully deployed

5 active deployments
Preview – evlog-telemetry — 3c82ff08 Deployed Oct 10, 2026 by vercel[bot]
Preview – evi — 3c82ff08 Deployed Oct 10, 2026 by vercel[bot]
Preview – evlog-docs — 3c82ff08 Deployed Oct 10, 2026 by vercel[bot]
Preview – just-use-evlog — 3c82ff08 Deployed Oct 10, 2026 by vercel[bot]
Preview – evlog-render-lab — 3c82ff08 Deployed Oct 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Built-in email redaction masks pnpm paths in stack traces (h3@1.15.11 → h***@***.11)

1 participant