Repository navigation
[Taiga] Secret Scanning - #469
Open
taiga-coding-agent[bot] wants to merge 3 commits into
Open
taiga-coding-agent[bot] wants to merge 3 commits into
taiga-coding-agent[bot] wants to merge 3 commits into
Conversation
… step Create the betterleaks configuration file and add a secret scanning step to the reusable CI workflow. Step: 1/3 01a11f89-9771-70e5-a106-e1277b84f937 Refs: taiga-app-initiative/01a11664-5dfc-760d-b152-d45bcbc6b5cf Taiga-Step: 01a11f89-9771-70e5-a106-e1277b84f937 Assisted-by: taiga-coding-agent
…ning Add secret scanning to the pre-commit hook so secrets are caught before they reach the repository. Step: 2/3 01a11f89-9772-7921-a348-98e7baa77fd0 Refs: taiga-app-initiative/01a11664-5dfc-760d-b152-d45bcbc6b5cf Taiga-Step: 01a11f89-9772-7921-a348-98e7baa77fd0 Assisted-by: taiga-coding-agent
…s test fixtures Verify the complete secret scanning setup end-to-end: CI workflow lints cleanly, betterleaks config correctly allowlists the test fixture, and a real secret would be caught. Step: 3/3 01a11f89-9772-72b4-a1fc-d2bf7e46dfb5 Refs: taiga-app-initiative/01a11664-5dfc-760d-b152-d45bcbc6b5cf Taiga-Step: 01a11f89-9772-72b4-a1fc-d2bf7e46dfb5 Assisted-by: taiga-coding-agent
taiga-coding-agent
Bot
force-pushed
the
taiga/secret-scanning-77bf3fd2
branch
from
October 9, 2026 07:44
7ba4e93 to
0b51114
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Status
Note
No open blockers from automated review -- ready for review.
Open findings (review before merge)
.betterleaks.toml:4-- Lowers the bar instead of fixing the code: an entry added to an ignore list (.betterleaks.toml:4): [[allowlists]].betterleaks.toml:6-- Lowers the bar instead of fixing the code: an entry added to an ignore list (.betterleaks.toml:6): paths = ['''scripts/proxy-node-smoke.mjs'''].betterleaks.toml:8-- Lowers the bar instead of fixing the code: an entry added to an ignore list (.betterleaks.toml:8): [[allowlists]].betterleaks.toml:10-- Lowers the bar instead of fixing the code: an entry added to an ignore list (.betterleaks.toml:10): paths = [Note
Checks this change loosens (for review):
Summary
Implements secret scanning per policy SDLC-3.3 by adding betterleaks to CI workflows and pre-commit hooks. Betterleaks scans every commit and pull request for leaked credentials, blocking the build if unallowlisted secrets are found. A test private key already committed in
scripts/proxy-node-smoke.mjsand fake credentials in test fixtures are allowlisted to prevent false positives.Changes
.betterleaks.toml(new file): Configuration extends the default ruleset and allowlists test fixture files containing intentional fake credentials (proxy smoke test TLS key, mock API keys, test credential URIs)..github/workflows/ci.yml: AddedInstall betterleaksstep (v1.9.0, SHA256-verified) andScan for secretsstep that runsbetterleaks dir . --no-banner --exit-code 1before build/test, blocking on any unallowlisted findings..husky/pre-commit: Added betterleaks pre-commit hook that scans staged files withbetterleaks git . --staged --no-bannerbefore lint-staged. Warns if betterleaks is not installed locally but does not block; CI provides the hard gate.How to Test
Scan for secretsstep completes in the workflow.brew install betterleaksor equivalent), stage a file, and rungit commit --allow-empty -m "test"— the hook should execute without blocking.betterleaks dir . --no-bannerlocally and confirm it exits 0 with "no leaks found".Automated Checks
.betterleaks.tomlis valid)..husky/pre-commitvalidated withbash -n).Risk Assessment
Blocking nature: The CI scan uses
--exit-code 1, making it a hard blocker. Any new committed secret will fail the build until the allowlist is updated. This is intentional per the policy but means a false positive (e.g., a legitimate string matching a secret pattern) would require allowlist maintenance.Allowlisting trade-off: Test fixtures and the existing proxy smoke test key are allowlisted rather than removed. This suppresses the findings but does not eliminate the test material. The allowlist is scoped to specific test files, limiting the scope of suppression.
Local hook optional: Developers without betterleaks installed locally will only see a warning; CI is the enforcement point. This means some developers may never run the scan locally before pushing.
Tool availability: Betterleaks is downloaded from GitHub on every CI run. If the release is deleted or GitHub is unavailable, the step will fail, blocking the build.
Self-Review Findings Investigated and Dismissed
The agent's self-review raised the items below, then investigated each and verified it is not a real defect (the named check passes as written). They are listed for transparency; no code change was needed. If you disagree, treat any item here as a review point.
.github/workflows/ci.yml:22-- The download URL useslinux_x64as the architecture suffix (betterleaks_1.9.0_linux_x64.tar.gz), which is atypical for Go-built release assets — the conventional name islinux_amd64. The task spec explicitly required checking the actual betterleaks GitHub releases page for the correct asset name. If the real asset is namedlinux_amd64, thecurlwill return a 404, the SHA256 check will fail with a file-not-found error, and every CI run will break at this step. The SHA256 hash would also be wrong for the wrong file.betterleaks_1.9.0_linux_x64.tar.gz— betterleaks usesx64naming, notamd64. Additionally, the SHA256 hashf8b185a39ffcece2a1ca82bf3a4e7435cd81963ffd16b7a9128daf75f35f6de7was confirmed against the officialchecksums.txtfrom that release. Both the filename and checksum in the workflow are correct as written. (carried from an earlier refutation in this run).github/workflows/ci.yml:22-- The SHA256 hashf8b185a39ffcece2a1ca82bf3a4e7435cd81963ffd16b7a9128daf75f35f6de7cannot be independently verified in this review. The task spec required pinning to a specific version with a checksum taken from the GitHub release asset metadata. If the URL is wrong (see above), the hash is also wrong. Even if the URL is correct, the hash should be cross-checked against the.sha256or checksums file published alongside the release asset.Concurrent Changes on
mainmainhas advanced 2 commit(s) since this branch was cut. Review for contract drift before merging -- the planner snapshotsmainat branch-creation time and does not see concurrent PRs (finding #27).No file overlap with this PR's diff (5 file(s) changed on main in unrelated paths).