chore(ci): add two-stage secret gate - #600
erinavllazagaj-eng wants to merge 1 commit into
Conversation
Stage 1 scans with betterleaks (advisory). Stage 2 triages with Kimi K3 and publishes the blocking 'AI secret verdict' commit status. Run 'deploy-secret-gate.sh arm runpod/runpod-python' after this merges.
| # No tick when a banner above already failed the gate: a green line under | ||
| # a red banner is the one mixed signal this comment must never send. | ||
| clean = not (review["injection"] or review["unanswered"] or blocked) | ||
| L += ["✅ No secrets in the changed files." if clean |
There was a problem hiding this comment.
False positive: clean is assigned on the line directly above, in the same if not findings: block, and is only read there.
| HTTP_TIMEOUT_S = 60 | ||
|
|
||
| def log(msg: str) -> None: | ||
| print(msg, flush=True) |
There was a problem hiding this comment.
False positive. All three sources are os.environ["TRUSTED_HEAD_REPO"] (= workflow_run.head_repository.full_name, a public owner/repo name); CodeQL's name heuristic treats identifiers containing "trusted" as secrets. The tokens and the Runpod key never reach log.
| "⚠️ **PR Security Scan did not finish cleanly** — the scanner errored " | ||
| "or a suppression was added. Resolve that before reading this.", |
There was a problem hiding this comment.
Fixed in runpod/secret_detector#23; it lands here when this branch is refreshed from the merged source. (literals parenthesised)
| "🚨 **The scanned source attempts to instruct the reviewer.** The " | ||
| "verdict below is unreliable; read the change by hand.", |
There was a problem hiding this comment.
Fixed in runpod/secret_detector#23; it lands here when this branch is refreshed from the merged source. (literals parenthesised)
| L += ["", "Rotate before anything else — the value is already in git " | ||
| "history and on GitHub's servers, so deleting the line does not " | ||
| "un-leak it.", ""] |
There was a problem hiding this comment.
Fixed in runpod/secret_detector#23; it lands here when this branch is refreshed from the merged source. (literals parenthesised)
| # on a runner that keeps running, so remove it rather than trusting that. | ||
| try: | ||
| os.remove(report_path) | ||
| except OSError: |
There was a problem hiding this comment.
Fixed in runpod/secret_detector#23; it lands here when this branch is refreshed from the merged source. (FileNotFoundError is ignored with a comment; any other OSError now logs a warning)
| "⚠️ **PR Security Scan did not finish cleanly** — the scanner errored " | ||
| "or a suppression was added. Resolve that before reading this.", |
There was a problem hiding this comment.
Fixed in runpod/secret_detector#23; it lands here when this branch is refreshed from the merged source. (literals parenthesised)
| "🚨 **The scanned source attempts to instruct the reviewer.** The " | ||
| "verdict below is unreliable; read the change by hand.", |
There was a problem hiding this comment.
Fixed in runpod/secret_detector#23; it lands here when this branch is refreshed from the merged source. (literals parenthesised)
| L += ["", "Rotate before anything else — the value is already in git " | ||
| "history and on GitHub's servers, so deleting the line does not " | ||
| "un-leak it.", ""] |
There was a problem hiding this comment.
Fixed in runpod/secret_detector#23; it lands here when this branch is refreshed from the merged source. (literals parenthesised)
| # on a runner that keeps running, so remove it rather than trusting that. | ||
| try: | ||
| os.remove(report_path) | ||
| except OSError: |
There was a problem hiding this comment.
Fixed in runpod/secret_detector#23; it lands here when this branch is refreshed from the merged source. (FileNotFoundError is ignored with a comment; any other OSError now logs a warning)
Adds the secret gate. Nothing blocks yet — the required-check ruleset is created separately by
deploy-secret-gate.sh arm runpod/runpod-pythonafter this merges.Owners: @runpod/security
Before merging, an admin must set the
KIMI_RUNPOD_API_KEYrepo secret. Without it stage 2 fails closed on every PR.