Repository navigation
Conversation
… baseline (#16942) #16875 added a second authApiKey key to all 11 locales without the scan, audit, strip step from RATCHET_BASELINES.md. Nine translations hashed to values already audited in their files; en ("API key") and ur did not, so Secret Detection (whole tree) fails on every branch that merges main. Followed the documented order on current main: full rescan (it found exactly these two and nothing else), both inspected and labelled is_secret false, line_number stripped. As sets the baseline gains two entries and loses none; the rest of the diff is the rescan's reordering.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 10 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe secrets baseline updates hashed ChangesSecret baseline refresh
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix · Severity of issue fixed: Medium Merge Risk: ⚪ Minimal · up to The refresh adds only the two intended audited locale findings and preserves the baseline format required by Secret Detection. The change is ready to merge. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
Full details: Linked Issues checkExplanation The changes address ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Verified — merge first, ahead of everything that has merged A secrets baseline is exactly where a real credential could be waved through, so the diff was checked as sets of findings keyed by
The two additions, both
Both are UI labels. detect-secrets' keyword plugin fires on the key name containing Root cause, for the record: #16875 added a second |
|
Closing as a duplicate of #16961, which fixes the same |
Closes #16942
Thinking Path
Secret Detection (whole tree)went red on #16916, which touches no locale file. The findings (en.json:9086,ur.json:9086, Secret Keyword) are the secondauthApiKeykey that #16875 added to all 11 locales. The base is red, so every PR that mergesmaininherits it. That makes this one unblocking PR rather than a fix per PR.Why only 2 of 11 locales: detect-secrets identifies a finding by
(file, type, hashed_secret). In nine locales the new translation hashed to a value already audited in that file.endid not: the new value is"API key"(lowercase k), while the older key is"API Key". Neither didur("API کیلید").They are UI labels, so the fix is the audited baseline. That is the documented mechanism, in
docs/developer/RATCHET_BASELINES.mdunder "The secrets baseline: scan, audit, strip". No plugin, filter or allowlist change, and the UI string is not reworded to dodge the keyword regex.What Changed
.secrets.baselineonly, produced by the documented order on currentmain:detect-secrets scan --baseline .secrets.baseline(v1.5.0, the pinned rev).is_secret: false.line_numberremoved from every entry.The diff looks large (+221/−207), but almost all of it is the rescan reordering entries by current line number, which step 1 always does.
Acceptance criteria
The rescan lists every finding missing from the audited baseline, and each is inspected. It found exactly two:
en.json:9086: Secret Keywordur.json:9086: Secret KeywordThey match the two CI findings on fix(kb): the RAPTOR tree is built at all, and its nodes cite their chunks (#14968) #16916. The scanner found those known positives, so its silence on the rest is a real result, not a scan that never looked.
Only confirmed non-secrets are labelled, and no
line_numberremains. Both hashes are recomputed from the visible labels:sha1("API key")=cf678cab…sha1("API کیلید")=9235d7ec…After the strip, entries not labelled
is_secret: false= 0, and entries carryingline_number= 0.Secret Detection (whole tree)passes on this PR. Pending this PR's own CI run.Verification
Old and new baselines compared as sets of
(file, type, hashed_secret, is_secret, is_verified):main)Outside
results, the only field that changed isgenerated_at.Model Used
Claude Opus 5 (
claude-opus-5)Summary by CodeRabbit