Skip to content

ONDC:SRV14 RootsGoods Logs (Next Iteration)#12

Open
ai-coder-dev wants to merge 5 commits intoONDC-Official:mainfrom
ai-coder-dev:main
Open

ONDC:SRV14 RootsGoods Logs (Next Iteration)#12
ai-coder-dev wants to merge 5 commits intoONDC-Official:mainfrom
ai-coder-dev:main

Conversation

@ai-coder-dev
Copy link

No description provided.

@gitguardian
Copy link

gitguardian bot commented Nov 26, 2025

⚠️ GitGuardian has uncovered 7 secrets following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

Since your pull request originates from a forked repository, GitGuardian is not able to associate the secrets uncovered with secret incidents on your GitGuardian dashboard.
Skipping this check run and merging your pull request will create secret incidents on your GitGuardian dashboard.

🔎 Detected hardcoded secrets in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
- - Generic High Entropy Secret 808a265 ONDC:SRV14/RootsGoods/Seller/flow1/on_status_report_shared.json View secret
- - Generic High Entropy Secret 3981ce5 ONDC:SRV14/RootsGoods/Seller/flow1/on_status_report_shared.json View secret
- - Generic High Entropy Secret 3981ce5 ONDC:SRV14/RootsGoods/Seller/flow1/on_confirm.json View secret
- - Generic High Entropy Secret 79f8ab0 ONDC:SRV14/RootsGoods/Seller/flow1/on_status_report_shared.json View secret
- - Generic High Entropy Secret 58202c3 ONDC:SRV14/RootsGoods/Seller/Merchant Cancellation Flow/on_confirm.json View secret
- - Generic High Entropy Secret 54db05c ONDC:SRV14/RootsGoods/Seller/flow1/on_confirm.json View secret
- - Generic High Entropy Secret 58202c3 ONDC:SRV14/RootsGoods/Seller/Buyer Cancellation Flow/on_confirm.json View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@vishal-ondc
Copy link

@ai-coder-dev @PradhyumnaS Please fix these small issues and then it will be good

Notes

  • Don't close the PR when you are raising the PR for next iteration, otherwise we can't maintain the trail
  • Don't send the any link which is not valid like items media url like https://rootsgoods.com/demo-video.mp4, if don't have then no need to send media key and also same apply for cred, if not have any valid certificate url then no need to send the creds and url like https://rootsgoods.com/certifications as it will break the buyer app
  • attach one cancellation flow
  • attach one failure flow
  • Hope you are accepting the status api call and responding with on_status even the report is in in-progress

on_select

  • Mistakenly I asked to remove quote but need to add so please add the quote in same way as on_init

on_status_form_filled

  • Transaction id should be same as select/on_select
  • Its timestamp should be in between the on_select and init but it has the next day date
  • items tags should be same as on_select in this call, we can't change it here
  • same date should be valid into fulfillments>time>range start and end align with the transaction date instead of next date
  • quote breakup doesn't have the selected items details that should be there and total quote should the sum of breakup

on_init

  • submission_id is missing under message>order>items>xinput>form_response

on_status_report_shared

  • xinput>form_response>submission_id is different from on_confirm submission_id, it should be same

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants