Skip to content

sec: regenerate .secrets.baseline to clear detect-secrets CI failure - #424

Merged
akshitpatel1732 merged 3 commits into
mainfrom
sec/regenerate-secrets-baseline-3
Sep 16, 2026
Merged

akshitpatel1732 merged 3 commits into
mainfrom
sec/regenerate-secrets-baseline-3

Conversation

@raaidrushdy

Copy link
Copy Markdown
Contributor

Summary

Regenerates .secrets.baseline to audit one new finding, clearing the detect-secrets CI check that's been failing on main since #420 was merged.

Type of Change

  • Security

Affected Components

(This PR touches only .secrets.baseline at the repo root.)

Motivation

The new CI-enforced detect-secrets check (#420) has been failing on every push to main since the merge because of one unaudited finding: an example password in security/reports/README_report_service.md documentation (not a real secret).

Testing Done

  • Unit tests pass locally
  • Tested manually - describe how:
    Ran detect-secrets scan --baseline .secrets.baseline, which surfaced the one new finding. Audited it with detect-secrets audit .secrets.baseline and confirmed it's a documentation example password, not a real secret, marked is_secret: false. Verified with detect-secrets audit .secrets.baseline reporting "Nothing to audit!" and confirmed the file is valid JSON.

Security Considerations

No new security exposure; this only updates metadata used by a secret-scanning tool.

Breaking Changes

  • No breaking changes

Rollback Plan

  • Revert commit is sufficient

Checklist

  • Code follows project conventions
  • No secrets, credentials, or tokens committed
  • Relevant documentation updated (if applicable)
  • CI/CD workflows pass on this branch
  • PR is focused on one thing

Screenshots

N/A - no UI impact.

@raaidrushdy
raaidrushdy requested a review from a team as a code owner September 15, 2026 11:17
@github-actions

Copy link
Copy Markdown
Contributor

Preview Environment

A preview environment can be spun up on demand for this PR.

Action Label Includes
Spin up preview deploy-preview Frontend, backend, database, Redis, OPA, worker
Spin up preview with M365 deploy-preview-m365 Everything above + PowerShell service for Exchange/Teams scan testing
Tear down preview teardown-preview Stops the environment early

The environment will also be torn down automatically when the PR is closed or merged.
Preview URLs will appear in a follow-up comment once the deploy completes (~5–8 min).
M365 scans require real tenant credentials added through the frontend UI.

@github-actions github-actions Bot added area: root Loose root-level files or IDE config size/S 10-99 lines changed labels Sep 15, 2026
Comment thread .secrets.baseline Fixed
@github-actions github-actions Bot added the needs-triage No reviewer has looked at this PR yet label Sep 15, 2026
@github-actions github-actions Bot added github_actions GitHub Actions related area: ci-cd Changes under /.github area: multi Touches more than one work area size/XL > 500 lines changed, or > 30 files changed and removed size/S 10-99 lines changed labels Sep 16, 2026
…s-baseline-3

# Conflicts:
#	.gitleaks-baseline.json
#	.secrets.baseline

@akshitpatel1732 akshitpatel1732 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @raaidrushdy for fixing the failing workflow.

@github-actions github-actions Bot removed the needs-triage No reviewer has looked at this PR yet label Sep 16, 2026
@akshitpatel1732
akshitpatel1732 merged commit 97765a5 into main Sep 16, 2026
14 checks passed
@github-actions
github-actions Bot deleted the sec/regenerate-secrets-baseline-3 branch September 16, 2026 08:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci-cd Changes under /.github area: multi Touches more than one work area area: root Loose root-level files or IDE config github_actions GitHub Actions related size/XL > 500 lines changed, or > 30 files changed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants