Private/Get-KadenPublishSafeFailure.ps1
|
function Get-KadenPublishSafeFailure { <# .SYNOPSIS Return a coded release failure, or a static fallback when the candidate is unsafe to show. #> [CmdletBinding()] param( [string]$Candidate, [Parameter(Mandatory = $true)] [string]$Fallback ) if ([string]::IsNullOrWhiteSpace($Candidate)) { return $Fallback } if ($Candidate -notmatch '^KDN-RELEASE-[A-Z0-9-]+: \S') { return $Fallback } $tokenPrefixes = @( 'ghp_[A-Za-z0-9]{20,}' 'gho_[A-Za-z0-9]{20,}' 'ghu_[A-Za-z0-9]{20,}' 'ghs_[A-Za-z0-9]{20,}' 'ghr_[A-Za-z0-9]{20,}' 'github_pat_[A-Za-z0-9_]{20,}' 'oy2[a-z0-9]{16,}' ) $pattern = '(?i)' + ($tokenPrefixes -join '|') if ($Candidate -match $pattern) { return $Fallback } return $Candidate } |