Repository navigation
fix(security): audit the orphan-secret-repair test fixture in .secrets.baseline - #17067
Conversation
…rets.baseline detect-secrets flags line 61's plaintext= keyword-adjacent test fixture (_PLAINTEXT = b"orphan-repair-plaintext-must-not-leak", a fake value) as a potential Secret Keyword finding. main never got a baseline entry for it when the file landed via #16927/#15779, so Secret Detection (whole tree) fails on any PR whose merge-ref includes it -- confirmed independently on #16643 and #17003. Audited as not a secret.
|
Warning Review limit reachedNext included review available in 57 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: mrveiss/AutoBot-AI/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: mrveiss/AutoBot-AI/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe ChangesSecret baseline update
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~2 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The baseline update should prevent the known false-positive secret-detection failure without changing production behavior. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…ges too (#17067) security.yml's pull_request path filter never included .secrets.baseline itself, so a baseline-only PR (like this one) never ran Secret Detection (whole tree) -- the one check that proves a baseline fix actually clears the red it's meant to fix. The secret-detection job is deliberately ungated once the workflow triggers, so fixing the outer on.pull_request.paths list is sufficient; no changes-job filter needed. Verified against pipeline-scripts/check_workflow_path_filters.py.
✅ SSOT Configuration Compliance: Passing🎉 No new hardcoded values of either class — Known backlog in |
…er-regression fix(security): strip the stray line_number field #17067 reintroduced into .secrets.baseline
Thinking Path
Secret Detection (whole tree)fails on any PR whose merge-ref includesautobot-backend/tests/migrations/test_orphan_secret_repair.py(landed via #16927/#15779): detect-secrets flags line 61'ssecret_type="api_key"keyword-adjacent argument as a potential Secret Keyword finding (confirmed: sha1("api_key") == the flagged hash, not the _PLAINTEXT fixture value), andmain's own.secrets.baselinenever got an entry for it. Confirmed independently as the root cause of new CI reds on two unrelated open PRs (#16643, #17003) whose synthetic merge-refs both pull in currentmain.What Changed
.secrets.baseline: added one audited entry (is_secret: false) for the one genuine finding attest_orphan_secret_repair.py:61, hash computed bydetect-secrets scan --baseline .secrets.baseline(version 1.5.0, matching CI's pin) against the real file content.Verification
git show origin/main:.secrets.baselinethat this is the only entry missing for this file (zero prior coverage).Single-issue rationale
No open issue tracks this specific baseline gap; it's a one-line infra fix blocking two unrelated PRs, not batchable with either.
Model Used
Claude Sonnet 5
Summary by CodeRabbit