Problem
detect-types inspects only the top-level structure of vault entries. Entries like Jenkins credential stores contain deeply nested structures with explicit type fields in sub-objects, but detection doesn't reach them.
Example structure (redacted)
vault_jenkins_credentials:
global:
credentials:
- type: gitLabApiTokenImpl
id: "..."
apiToken: "..."
- type: usernamePassword
id: "..."
username: "..."
password: "..."
- type: string
id: "..."
secret: "..."
- type: azure
id: "..."
subscriptionId: "..."
clientId: "..."
clientSecret: "..."
domains:
- name: "..."
credentials:
- type: usernamePassword
...
Current detection classifies this as usernamePassword (medium) based on the key name pattern — missing the rich type information already present in the sub-objects.
Expected behavior
- Recognize nested credential container patterns (
*.credentials[])
- Read explicit
type fields from sub-objects
- Report a summary of contained credential types, e.g.:
vault_jenkins_credentials → credentialStore (high)
contains: 6x usernamePassword, 4x string, 1x gitLabApiTokenImpl, 1x azure
- Support Jenkins-style structures (
global.credentials, domains[].credentials)
Context
This pattern comes from Ansible roles that manage Jenkins credentials via JCasC (Jenkins Configuration as Code). The vault entry mirrors the Jenkins credential domain hierarchy.
Acceptance criteria
Problem
detect-typesinspects only the top-level structure of vault entries. Entries like Jenkins credential stores contain deeply nested structures with explicittypefields in sub-objects, but detection doesn't reach them.Example structure (redacted)
Current detection classifies this as
usernamePassword (medium)based on the key name pattern — missing the rich type information already present in the sub-objects.Expected behavior
*.credentials[])typefields from sub-objectsglobal.credentials,domains[].credentials)Context
This pattern comes from Ansible roles that manage Jenkins credentials via JCasC (Jenkins Configuration as Code). The vault entry mirrors the Jenkins credential domain hierarchy.
Acceptance criteria
credentials[]list patterns with typed sub-objectscredentialStore) for entries with multiple nested credentialsdetect-typesoutput