Skip to content

feat: restrict requirements for enhanced secret scan matches #6379

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

aitchiss
Copy link
Contributor

🎉 Thanks for submitting a pull request! 🎉

Summary

Fixes https://linear.app/netlify/issue/WRFL-2581/tighten-up-requirements-to-be-considered-a-secret-to-prevent-false

Secrets must now:

  • Start with a delimiter such as quotes, backticks, equals
  • Contain only alphanumeric chars or dashes in the sequence after the prefix

For us to review and ship your PR efficiently, please perform the following steps:

  • Open a bug/issue before writing your code 🧑‍💻. This ensures
    we can discuss the changes and get feedback from everyone that should be involved. If you`re fixing a typo or
    something that`s on fire 🔥 (e.g. incident related), you can skip this step.
  • Read the contribution guidelines 📖. This ensures
    your code follows our style guide and passes our tests.
  • Update or add tests (if any source code was changed or added) 🧪
  • Update or add documentation (if features were changed or added) 📝
  • Make sure the status checks below are successful ✅

A picture of a cute animal (not mandatory, but encouraged)

@aitchiss aitchiss requested a review from a team as a code owner May 23, 2025 14:46
Copy link
Contributor

This pull request adds or modifies JavaScript (.js, .cjs, .mjs) files.
Consider converting them to TypeScript.

Comment on lines 77 to 79
'key="ghp_123456789012345678"', // GitHub personal access token
'key="sk_123456789012345678"', // Stripe key
'key="aws_123456789012345678"', // AWS access key

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Does the regex work if there's whitespace around the =?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

it does, as long as there's open quotes (single, double or backticks), I've added a test case for that!

Copy link
Contributor

This pull request adds or modifies JavaScript (.js, .cjs, .mjs) files.
Consider converting them to TypeScript.

1 similar comment
Copy link
Contributor

This pull request adds or modifies JavaScript (.js, .cjs, .mjs) files.
Consider converting them to TypeScript.

Copy link
Contributor

This pull request adds or modifies JavaScript (.js, .cjs, .mjs) files.
Consider converting them to TypeScript.

Copy link
Contributor

This pull request adds or modifies JavaScript (.js, .cjs, .mjs) files.
Consider converting them to TypeScript.

Copy link
Contributor

This pull request adds or modifies JavaScript (.js, .cjs, .mjs) files.
Consider converting them to TypeScript.

@aitchiss aitchiss enabled auto-merge (squash) May 29, 2025 14:17
@aitchiss aitchiss merged commit a976d15 into main May 29, 2025
59 of 61 checks passed
@aitchiss aitchiss deleted the suzanne/wrfl-2581-tighten-up-requirements-to-be-considered-a-secret-to-prevent branch May 29, 2025 14:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants