Skip to content

Add detect-secrets scanning - #34

Merged
reevejd merged 1 commit into
masterfrom
detect-secrets-setup
Sep 15, 2026
Merged

reevejd merged 1 commit into
masterfrom
detect-secrets-setup

Conversation

@reevejd

@reevejd reevejd commented Sep 15, 2026

Copy link
Copy Markdown
Member

Sets up IBM detect-secrets with an audited baseline and a pre-commit hook.

https://jsw.ibm.com/browse/SKILLS-131558

Findings

  1. charts/pontoon/README.md:62: [Basic Auth Credentials] Local-only connection string with throwaway words (username/password)
  2. charts/pontoon/values-demo.yaml:20: [Secret Keyword] Obvious placeholder "ramdompassword" with "# change me" comment
  3. charts/pontoon/values-demo.yaml:25: [Secret Keyword] Obvious placeholder "randompassword" with "# change me" comment
  4. charts/pontoon/values-unsafe.yaml:21: [Secret Keyword] Obvious placeholder "ramdompassword" (typo)

Repo state

  • Path taken: P (pre-commit)
  • Package manager: None (no package.json)
  • Husky version: N/A
  • core.hooksPath (local): Not set
  • Baseline: 4 findings, 4 audited, 0 real
  • Hook test: secret blocked (exit 1), clean file allowed (exit 0)

@reevejd
reevejd requested a review from a team as a code owner September 15, 2026 04:50
@reevejd
reevejd merged commit 6111652 into master Sep 15, 2026
6 checks passed
@reevejd
reevejd deleted the detect-secrets-setup branch September 15, 2026 04:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant