Skip to content

[Taiga] Secret Scanning - #469

Open
taiga-coding-agent[bot] wants to merge 3 commits into
mainfrom
taiga/secret-scanning-77bf3fd2
Open

taiga-coding-agent[bot] wants to merge 3 commits into
mainfrom
taiga/secret-scanning-77bf3fd2

Conversation

@taiga-coding-agent

@taiga-coding-agent taiga-coding-agent Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Status

Note

No open blockers from automated review -- ready for review.

Open findings (review before merge)

  • [correctness] .betterleaks.toml:4 -- Lowers the bar instead of fixing the code: an entry added to an ignore list (.betterleaks.toml:4): [[allowlists]]
    • Suggested fix: Fix the cause, not the check: undo this change and correct the code (or, for a generated module, the step that generates it). If the finding it silences is wrong, leave the check as it was and refute the finding, naming the verification you ran.
  • [correctness] .betterleaks.toml:6 -- Lowers the bar instead of fixing the code: an entry added to an ignore list (.betterleaks.toml:6): paths = ['''scripts/proxy-node-smoke.mjs''']
    • Suggested fix: Fix the cause, not the check: undo this change and correct the code (or, for a generated module, the step that generates it). If the finding it silences is wrong, leave the check as it was and refute the finding, naming the verification you ran.
  • [correctness] .betterleaks.toml:8 -- Lowers the bar instead of fixing the code: an entry added to an ignore list (.betterleaks.toml:8): [[allowlists]]
    • Suggested fix: Fix the cause, not the check: undo this change and correct the code (or, for a generated module, the step that generates it). If the finding it silences is wrong, leave the check as it was and refute the finding, naming the verification you ran.
  • [correctness] .betterleaks.toml:10 -- Lowers the bar instead of fixing the code: an entry added to an ignore list (.betterleaks.toml:10): paths = [
    • Suggested fix: Fix the cause, not the check: undo this change and correct the code (or, for a generated module, the step that generates it). If the finding it silences is wrong, leave the check as it was and refute the finding, naming the verification you ran.

Note

Checks this change loosens (for review):

  • Lowers the bar instead of fixing the code: an entry added to an ignore list (.betterleaks.toml:4): [[allowlists]]
  • Lowers the bar instead of fixing the code: an entry added to an ignore list (.betterleaks.toml:6): paths = ['''scripts/proxy-node-smoke.mjs''']
  • Lowers the bar instead of fixing the code: an entry added to an ignore list (.betterleaks.toml:8): [[allowlists]]
  • Lowers the bar instead of fixing the code: an entry added to an ignore list (.betterleaks.toml:10): paths = [

Summary

Implements secret scanning per policy SDLC-3.3 by adding betterleaks to CI workflows and pre-commit hooks. Betterleaks scans every commit and pull request for leaked credentials, blocking the build if unallowlisted secrets are found. A test private key already committed in scripts/proxy-node-smoke.mjs and fake credentials in test fixtures are allowlisted to prevent false positives.

Changes

  • .betterleaks.toml (new file): Configuration extends the default ruleset and allowlists test fixture files containing intentional fake credentials (proxy smoke test TLS key, mock API keys, test credential URIs).
  • .github/workflows/ci.yml: Added Install betterleaks step (v1.9.0, SHA256-verified) and Scan for secrets step that runs betterleaks dir . --no-banner --exit-code 1 before build/test, blocking on any unallowlisted findings.
  • .husky/pre-commit: Added betterleaks pre-commit hook that scans staged files with betterleaks git . --staged --no-banner before lint-staged. Warns if betterleaks is not installed locally but does not block; CI provides the hard gate.

How to Test

  1. Verify the CI scan runs: Push a branch and confirm the Scan for secrets step completes in the workflow.
  2. Verify the pre-commit hook runs: Install betterleaks locally (brew install betterleaks or equivalent), stage a file, and run git commit --allow-empty -m "test" — the hook should execute without blocking.
  3. Verify allowlisting works: Run betterleaks dir . --no-banner locally and confirm it exits 0 with "no leaks found".
  4. Verify blocking on new secrets: Add a fake secret to a non-allowlisted file, stage it, and attempt to commit — the pre-commit hook should block; push to a branch and confirm CI blocks as well.

Automated Checks

  • Betterleaks scan: Passed (exit 0, no unallowlisted findings after allowlist entries added).
  • Actionlint on CI workflow: Passed (no syntax errors).
  • TOML validation: Passed (.betterleaks.toml is valid).
  • Shell syntax: Passed (.husky/pre-commit validated with bash -n).

Risk Assessment

Blocking nature: The CI scan uses --exit-code 1, making it a hard blocker. Any new committed secret will fail the build until the allowlist is updated. This is intentional per the policy but means a false positive (e.g., a legitimate string matching a secret pattern) would require allowlist maintenance.

Allowlisting trade-off: Test fixtures and the existing proxy smoke test key are allowlisted rather than removed. This suppresses the findings but does not eliminate the test material. The allowlist is scoped to specific test files, limiting the scope of suppression.

Local hook optional: Developers without betterleaks installed locally will only see a warning; CI is the enforcement point. This means some developers may never run the scan locally before pushing.

Tool availability: Betterleaks is downloaded from GitHub on every CI run. If the release is deleted or GitHub is unavailable, the step will fail, blocking the build.

Self-Review Findings Investigated and Dismissed

The agent's self-review raised the items below, then investigated each and verified it is not a real defect (the named check passes as written). They are listed for transparency; no code change was needed. If you disagree, treat any item here as a review point.

  • [CRITICAL/CORRECTNESS] .github/workflows/ci.yml:22 -- The download URL uses linux_x64 as the architecture suffix (betterleaks_1.9.0_linux_x64.tar.gz), which is atypical for Go-built release assets — the conventional name is linux_amd64. The task spec explicitly required checking the actual betterleaks GitHub releases page for the correct asset name. If the real asset is named linux_amd64, the curl will return a 404, the SHA256 check will fail with a file-not-found error, and every CI run will break at this step. The SHA256 hash would also be wrong for the wrong file.
    • Why dismissed: Verified against the GitHub Releases API (https://api.github.com/repos/betterleaks/betterleaks/releases/tags/v1.9.0): the actual asset is named betterleaks_1.9.0_linux_x64.tar.gz — betterleaks uses x64 naming, not amd64. Additionally, the SHA256 hash f8b185a39ffcece2a1ca82bf3a4e7435cd81963ffd16b7a9128daf75f35f6de7 was confirmed against the official checksums.txt from that release. Both the filename and checksum in the workflow are correct as written. (carried from an earlier refutation in this run)
  • [MAJOR/CORRECTNESS] .github/workflows/ci.yml:22 -- The SHA256 hash f8b185a39ffcece2a1ca82bf3a4e7435cd81963ffd16b7a9128daf75f35f6de7 cannot be independently verified in this review. The task spec required pinning to a specific version with a checksum taken from the GitHub release asset metadata. If the URL is wrong (see above), the hash is also wrong. Even if the URL is correct, the hash should be cross-checked against the .sha256 or checksums file published alongside the release asset.

Concurrent Changes on main

main has advanced 2 commit(s) since this branch was cut. Review for contract drift before merging -- the planner snapshots main at branch-creation time and does not see concurrent PRs (finding #27).

No file overlap with this PR's diff (5 file(s) changed on main in unrelated paths).

taiga-agent Bot added 3 commits October 9, 2026 07:32
… step

Create the betterleaks configuration file and add a secret scanning step to the reusable CI workflow.

Step: 1/3 01a11f89-9771-70e5-a106-e1277b84f937
Refs: taiga-app-initiative/01a11664-5dfc-760d-b152-d45bcbc6b5cf
Taiga-Step: 01a11f89-9771-70e5-a106-e1277b84f937
Assisted-by: taiga-coding-agent
…ning

Add secret scanning to the pre-commit hook so secrets are caught before they reach the repository.

Step: 2/3 01a11f89-9772-7921-a348-98e7baa77fd0
Refs: taiga-app-initiative/01a11664-5dfc-760d-b152-d45bcbc6b5cf
Taiga-Step: 01a11f89-9772-7921-a348-98e7baa77fd0
Assisted-by: taiga-coding-agent
…s test fixtures

Verify the complete secret scanning setup end-to-end: CI workflow lints cleanly, betterleaks config correctly allowlists the test fixture, and a real secret would be caught.

Step: 3/3 01a11f89-9772-72b4-a1fc-d2bf7e46dfb5
Refs: taiga-app-initiative/01a11664-5dfc-760d-b152-d45bcbc6b5cf
Taiga-Step: 01a11f89-9772-72b4-a1fc-d2bf7e46dfb5
Assisted-by: taiga-coding-agent
@taiga-coding-agent
taiga-coding-agent Bot force-pushed the taiga/secret-scanning-77bf3fd2 branch from 7ba4e93 to 0b51114 Compare October 9, 2026 07:44
@taiga-coding-agent
taiga-coding-agent Bot marked this pull request as ready for review October 9, 2026 07:44

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants