ci: gate on ruff and the secret scan #248
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!248
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "ci/gate-ruff-and-gitleaks"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Adds the two gating steps that were deliberately held back until the runner image was re-baked
(#61, #62). The image now carries both binaries — the bake's sanity check printed
ruff 0.16.0andgitleaks 8.30.1.ruff check .(#61)Lints ~2 000 lines of Python that nothing checked before, including
controller.py(1 192 lines)which provisions and deletes ephemeral CI VMs and whose own comments record two production
incidents. Rule selection and its rationale live in
ruff.toml, merged earlier; the repo is alreadyclean, so this goes in green.
Path-gated on
ansibleorscripts— unlike the neighbouring Ansible steps, since Python livesunder both.
gitleaks git(#62)Full-history secret scan. This repo already checks out with
fetch-depth: 0for thechange-detection step, so the scan sees every commit rather than a shallow tip — worth stating,
because a depth-1 clone would make the gate pass while inspecting almost nothing.
Not path-gated: a secret can appear in any file type, so gating it on "did Ansible change" would
defeat the point.
--redactso a finding reports location and rule but never the value.bitborg-infra's history is clean — notably including the period of the Glesys credential
incident, so those values were never committed. That was the main unknown when #62 was written.
Verified
Both commands run locally against this tree:
ruff check .→All checks passed!,gitleaks git→no leaks found(154ms).format:check,mdlintandshellcheckalso pass.Refs #61, #62