Files
Keysat c898ad8530 redaction: \b after magnitude so amounts don't eat the next word (v0.1.0:57)
The currency-anchored amount regexes treated a single-letter magnitude
suffix (k/m/b) as optional but unbounded, so "$5,000,000 but" scrubbed to
"[AMOUNT_1]ut" — the 'b' of "but" was consumed as a 'billion' suffix. Add a
word boundary after _MAG on the three currency-anchored _AMOUNT_RES patterns
(range, symbol, ISO-code); the worded-amount pattern is unaffected. Money
still tokenizes in every case ($5m/$5b/$3-5M/USD 5,000,000); only the OUTBOUND
to-Claude text stops losing the leading letter of the following word.
Round-trips were already lossless.

Regression-locked by a round-5 section in test_scrub_leak.py; full redaction
suite (scrub_leak + reidentification + grounding_boundary) green. Packaged as
StartOS v0.1.0:57. Reported by the Spark gateway dev; gateway re-vendored
scrub.py verbatim for parity (same golden-file leak test gates both sides).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-05 18:52:04 -05:00

19 lines
908 B
TypeScript

import { VersionInfo } from '@start9labs/start-sdk'
// Redaction engine fix: the amount/magnitude regex no longer swallows the first
// letter of a following word. '$5,000,000 but' was scrubbing to '[AMOUNT_1]ut'
// because the single-letter 'b' (billion) suffix matched the 'b' of 'but'; a word
// boundary after the magnitude restores it. Round-trips were already lossless; this
// keeps the *outbound* (to-Claude) text from losing a word. No data migration.
export const v_0_1_0_57 = VersionInfo.of({
version: '0.1.0:57',
releaseNotes: {
en_US: [
'Redaction fix: a dollar amount immediately followed by a word (e.g. "$5,000,000',
'but") no longer eats the first letter of that word when de-identifying text sent',
'to the Architect. Real magnitude suffixes ($5m, $5b, $3-5M) still tokenize.',
].join(' '),
},
migrations: { up: async () => {}, down: async () => {} },
})