-
Notifications
You must be signed in to change notification settings - Fork 78
feat: introduce enhanced secret scanning #6230
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat: introduce enhanced secret scanning #6230
Conversation
This pull request adds or modifies JavaScript ( |
This pull request adds or modifies JavaScript ( |
This pull request adds or modifies JavaScript ( |
* @param val env var value | ||
* @returns boolean | ||
*/ | ||
function isLikelySecretValue(val): boolean { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is pretty simplistic at the moment, but the idea is to catch the low-hanging fruit for now and build on it more later
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Left a few comments, but none are blockers.
This pull request adds or modifies JavaScript ( |
1 similar comment
This pull request adds or modifies JavaScript ( |
This pull request adds or modifies JavaScript ( |
This pull request adds or modifies JavaScript ( |
This pull request adds or modifies JavaScript ( |
This pull request adds or modifies JavaScript ( |
1 similar comment
This pull request adds or modifies JavaScript ( |
🎉 Thanks for submitting a pull request! 🎉
Summary
Closes https://linear.app/netlify/issue/WRFL-2392/update-secret-scanning-to-be-more-generic
If BB sends
enhancedSecretScan
we conduct a minimal check on env var values that have prefixes known to indicate a private key. We'll likely expand on this in future for more sophisticated detection but it's just a first MVP.For us to review and ship your PR efficiently, please perform the following steps:
we can discuss the changes and get feedback from everyone that should be involved. If you`re fixing a typo or
something that`s on fire 🔥 (e.g. incident related), you can skip this step.
your code follows our style guide and passes our tests.
A picture of a cute animal (not mandatory, but encouraged)