secrets
4 guardrails, all at version v1.
| Guardrail | Default severity | What it checks |
|---|---|---|
secrets/detector-ran | error | A secret detector ran on the checkout, or left a report the build can be judged on, so something has actually looked for credentials. |
secrets/gitignore-present | warning | The repository has a .gitignore, so the next person who runs git add . doesn't commit build output or the local credential files next to it. |
secrets/no-credential-files-committed | error | None of the well-known credential files is in the working tree: no .env, private key, keystore, kubeconfig or cloud credential file. |
secrets/no-hardcoded-credentials | error | Every secret the detector reported is below the severity the team gates on, or matches a rule the team has already accepted. |
You configure every guardrail in this category the same way, in the guardrails.checks array of buildnote.json. Configuring guardrails lists every option, and Guardrails lets you search the whole library.