Skip to content

SK-3014-gitleaks-detection-fix-added-script-to-fix-generated-files - #282

Merged
skyflow-himanshupal merged 7 commits into
mainfrom
himanshupal/SK-3014-gitleaks-detection-multiple-secret-exposures-identified-across-repository-skyflow-python
Sep 24, 2026
Merged

skyflow-himanshupal merged 7 commits into
mainfrom
himanshupal/SK-3014-gitleaks-detection-multiple-secret-exposures-identified-across-repository-skyflow-python

Conversation

@skyflow-himanshupal

@skyflow-himanshupal skyflow-himanshupal commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Fern regenerates the four vault client trees (common/generated, skyflow/generated, skyvault/skyflow/generated, flowvault/skyflow/generated) from scratch, so realistic-looking example secrets in their
docstrings (a fake JWT, fake token UUIDs) keep re-triggering gitleaks on every regen. Hand-fixing them doesn't stick. This PR adds automated detection, redaction, and enforcement so this stops being a recurring manual
chore.

What's included

  • scripts/patch_generated_secrets.py — runs the real gitleaks binary against .gitleaks.toml and auto-redacts whatever it flags across all four generated trees, rather than hand-maintaining a list of
    known-bad strings. Redacts by position (not by the matched text itself) so it can't corrupt surrounding quotes or trip CodeQL's clear-text-storage/logging checks, self-tests the local gitleaks build's allowlist
    support before trusting it, verifies with ast.parse, and rolls back cleanly on any failure (including a failed final re-scan).
  • .githooks/pre-commit — two-tier local guard: tier 1 runs the script above and stages only what it actually redacted (plus whatever you'd already staged); tier 2 runs gitleaks protect --staged and blocks the
    commit on anything left over.
  • scripts/install_git_hooks.sh — one-time setup (git config core.hooksPath .githooks); pip has no npm-style prepare hook to wire this automatically.
  • .github/workflows/gitleaks-auto-redact.yml (new) — runs the same auto-redaction on every PR push and commits the fix straight back to the branch. Closes the gap for contributors without gitleaks installed
    locally.
  • .github/workflows/Gitleaks.yml (new) — scans every PR, comments findings, and fails the check if it finds anything. This repo had no gitleaks CI coverage at all before this PR.
  • .gitleaks.toml — added an allowlist for tests/dummy-non-secret/*, intentional non-secret fixture data.
  • Manually redacted the fake JWT/token examples already present in the generated auth and token clients, plus adjusted a couple of test fixtures that were tripping the same rules.

Testing

  • Verified end-to-end against real and scratch repos: redaction, rollback, self-test, and idempotency all pass.
  • Confirmed the local hook no longer sweeps unrelated working-tree changes into a commit.
  • Confirmed CI now blocks on real findings and self-heals once the auto-redact commit lands.

Comment thread scripts/patch_generated_secrets.py Fixed
Comment thread scripts/patch_generated_secrets.py Fixed
Comment thread scripts/patch_generated_secrets.py Fixed
Comment thread scripts/patch_generated_secrets.py Fixed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved moderate issues affect redaction correctness, staging safety, and secret-scan enforcement.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 Medium severity

Open (2)
What changed in this PR

Adds automated gitleaks redaction for generated Python files and an opt-in pre-commit guard.

Changes:

  • Adds secret detection, redaction, validation, and rescanning.
  • Adds Git hook installation and staged scanning.
  • Replaces generated JWT examples with placeholders.
File Summary
scripts/​patch_generated_secrets.py Implements redaction and verification; duplicate spans, subprocess failures, and missing test coverage remain.
scripts/​install_git_hooks.sh Configures repository-local Git hooks.
common/​generated/​rest/​authentication/​client.py Replaces generated JWT examples with placeholders.
.githooks/​pre-commit Runs redaction and staged scans; contains invalid path staging, unintended staging side effects, and an unenforced CI fallback.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .githooks/pre-commit Outdated
Comment thread scripts/patch_generated_secrets.py Outdated
@github-actions

Copy link
Copy Markdown

✅ Gitleaks Findings: No secrets detected. Safe to proceed!

Comment thread .github/workflows/gitleaks-auto-redact.yml Fixed
@github-actions

Copy link
Copy Markdown

✅ Gitleaks Findings: No secrets detected. Safe to proceed!

@skyflow-himanshupal
skyflow-himanshupal merged commit 2925cc2 into main Sep 24, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants