ci: gate on ruff and the secret scan #248

Sammanfogat
supernaut sammanfogade 1 incheckning från ci/gate-ruff-and-gitleaks in i main 2026-07-29 21:23:49 +00:00
Ägare

Adds the two gating steps that were deliberately held back until the runner image was re-baked
(#61, #62). The image now carries both binaries — the bake's sanity check printed ruff 0.16.0 and
gitleaks 8.30.1.

ruff check . (#61)

Lints ~2 000 lines of Python that nothing checked before, including controller.py (1 192 lines)
which provisions and deletes ephemeral CI VMs and whose own comments record two production
incidents. Rule selection and its rationale live in ruff.toml, merged earlier; the repo is already
clean, so this goes in green.

Path-gated on ansible or scripts — unlike the neighbouring Ansible steps, since Python lives
under both.

gitleaks git (#62)

Full-history secret scan. This repo already checks out with fetch-depth: 0 for the
change-detection step, so the scan sees every commit rather than a shallow tip — worth stating,
because a depth-1 clone would make the gate pass while inspecting almost nothing.

Not path-gated: a secret can appear in any file type, so gating it on "did Ansible change" would
defeat the point.

--redact so a finding reports location and rule but never the value.

bitborg-infra's history is clean — notably including the period of the Glesys credential
incident, so those values were never committed. That was the main unknown when #62 was written.

Verified

Both commands run locally against this tree: ruff check . → All checks passed!,
gitleaks git → no leaks found (154ms). format:check, mdlint and shellcheck also pass.

Refs #61, #62

Adds the two gating steps that were deliberately held back until the runner image was re-baked (#61, #62). The image now carries both binaries — the bake's sanity check printed `ruff 0.16.0` and `gitleaks 8.30.1`. ## `ruff check .` (#61) Lints ~2 000 lines of Python that nothing checked before, including `controller.py` (1 192 lines) which provisions and **deletes** ephemeral CI VMs and whose own comments record two production incidents. Rule selection and its rationale live in `ruff.toml`, merged earlier; the repo is already clean, so this goes in green. Path-gated on `ansible` **or** `scripts` — unlike the neighbouring Ansible steps, since Python lives under both. ## `gitleaks git` (#62) Full-history secret scan. This repo already checks out with `fetch-depth: 0` for the change-detection step, so the scan sees every commit rather than a shallow tip — worth stating, because a depth-1 clone would make the gate pass while inspecting almost nothing. Not path-gated: a secret can appear in any file type, so gating it on "did Ansible change" would defeat the point. `--redact` so a finding reports location and rule but never the value. **bitborg-infra's history is clean** — notably including the period of the Glesys credential incident, so those values were never committed. That was the main unknown when #62 was written. ## Verified Both commands run locally against this tree: `ruff check .` → `All checks passed!`, `gitleaks git` → `no leaks found` (154ms). `format:check`, `mdlint` and `shellcheck` also pass. Refs #61, #62
supernaut lade till 1 incheckning 2026-07-29 21:19:35 +00:00
ci: gate on ruff and the secret scan
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m32s
0980129b02
supernaut sammanfogade incheckning 6e2c4e5f3a till main 2026-07-29 21:23:49 +00:00
supernaut tog bort grenen ci/gate-ruff-and-gitleaks 2026-07-29 21:23:49 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-07-29 21:23:51 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-08-03 09:41:34 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!248
Ingen beskrivning angiven.