Skip to content

Add detect-secrets scanning - #89

Merged
reevejd merged 1 commit into
mainfrom
detect-secrets-setup
Sep 15, 2026
Merged

reevejd merged 1 commit into
mainfrom
detect-secrets-setup

Conversation

@reevejd

@reevejd reevejd commented Sep 15, 2026

Copy link
Copy Markdown
Member

Sets up IBM detect-secrets with an audited baseline and a pre-commit hook.

https://jsw.ibm.com/browse/SKILLS-131558

Findings

.github/workflows/rspec-tests.yml:73: Basic Auth Credentials, not a secret, local-only connection string (root:password@127.0.0.1)
docker-compose.yml:6: Secret Keyword, not a secret, obvious placeholder ("password" literal)
spec/dummy/config/database.yml:23: Basic Auth Credentials, not a secret, local-only connection string (postgres:password@localhost)
spec/dummy/config/database.yml:68: Basic Auth Credentials, not a secret, local-only connection string in comment (myuser:mypass@localhost)
spec/spec_helper.rb:13: Basic Auth Credentials, not a secret, local-only connection string (postgres:password@localhost)

Repo state

  • Path taken: P (pre-commit framework)
  • Package manager: none (Ruby/Gem project)
  • Husky version: none
  • core.hooksPath (local): (none)
  • Baseline: 5 findings, 5 audited, 0 real
  • Hook test: secret blocked (exit 1), clean file allowed (exit 0)

@reevejd
reevejd requested a review from a team as a code owner September 15, 2026 04:42
@reevejd
reevejd merged commit 70b3f18 into main Sep 15, 2026
9 checks passed
@reevejd
reevejd deleted the detect-secrets-setup branch September 15, 2026 04:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant