fix(ci): make the hardcoded-secret scan blocking and close the .gitignore/.sops.yaml gaps that let a plaintext deploy key through — also untracks tfplan binaries and skills-lock.json
This commit is contained in:
+3
-1
@@ -1,3 +1,5 @@
|
||||
creation_rules:
|
||||
- path_regex: k8s/.*secrets.*\.ya?ml
|
||||
# `secrets?` — singular too. A `seed-repo-secret.yaml` once slipped this regex
|
||||
# and was committed in plaintext to a public remote.
|
||||
- path_regex: k8s/.*secrets?.*\.ya?ml
|
||||
age: age1e5fq3hwxy78psus2nfvmtmua36g0u3suk78ephw6246l974d2utsvn0hla
|
||||
|
||||
Reference in New Issue
Block a user