feat(security): commit-time secret guard that FAILS the build on a committed credential #130

Closed
abiba-bot wants to merge 0 commits from fm/commit-time-secret-guard-20260917 into master
Owner

The 2026-09-17 purge removed six live credentials that had sat in this repo for weeks. Nothing blocked that class of commit, so a warning in a stream nobody reads was the only signal. This adds a guard that fails the build instead of warning.

Guard:

  • scripts/secret-scan.sh: bash + coreutils + grep/sed/awk + git only
  • scripts/secret-patterns.tsv: checked-in pattern list
  • scripts/secret-allowlist.tsv: one entry per deliberate synthetic example, each with a reason
  • A small inert-value classifier drops env refs, paths, dotted code access

Wiring:

  • .gitea/workflows/pr-pipeline.yaml: explicit "Committed-credential scan" step
  • scripts/prose-lint.sh: "Secret scan" section

Tests:

  • tests/test_secret_scan.sh: 20 cases
The 2026-09-17 purge removed six live credentials that had sat in this repo for weeks. Nothing blocked that class of commit, so a warning in a stream nobody reads was the only signal. This adds a guard that fails the build instead of warning. Guard: - scripts/secret-scan.sh: bash + coreutils + grep/sed/awk + git only - scripts/secret-patterns.tsv: checked-in pattern list - scripts/secret-allowlist.tsv: one entry per deliberate synthetic example, each with a reason - A small inert-value classifier drops env refs, paths, dotted code access Wiring: - .gitea/workflows/pr-pipeline.yaml: explicit "Committed-credential scan" step - scripts/prose-lint.sh: "Secret scan" section Tests: - tests/test_secret_scan.sh: 20 cases
Author
Owner

Closing as redundant rather than merging: this branch is 0 commits ahead of master and 0 files differ (verified via the compare API). The committed-credential scan step is already live on master in .gitea/workflows/pr-pipeline.yaml (bash scripts/secret-scan.sh), so the guard this PR adds is already in place. No content is lost.

Closing as redundant rather than merging: this branch is 0 commits ahead of master and 0 files differ (verified via the compare API). The committed-credential scan step is already live on master in `.gitea/workflows/pr-pipeline.yaml` (`bash scripts/secret-scan.sh`), so the guard this PR adds is already in place. No content is lost.
abiba-bot closed this pull request 2026-09-26 15:47:51 +00:00

Pull request closed

Please reopen this pull request to perform a merge.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SyslogSolution/prose-contracts#130