Repository ignores what it must not commit
secrets/gitignore-present@v1
The repository has a .gitignore, so the next person who runs git add . doesn't commit build output or the local credential files next to it.
| Id | secrets/gitignore-present |
| Version | v1 |
| Category | secrets |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | files |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
files | Presence, size and line counts of the well known files a repository is expected to carry, plus any extra path the guardrail asks for. | path |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "secrets/gitignore-present@v1",
"severity": "warning",
"with": {
"path": ".gitignore",
"minLines": "1"
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
path | Path to the ignore file, relative to the directory the CLI runs in. | .gitignore | GUARDRAIL_INPUT_PATH |
minLines | Fewest non-blank lines the file must have to count as written. | 1 | GUARDRAIL_INPUT_MINLINES |
How to fix
Add a .gitignore at the repository root that covers build output and local configuration:
build/
.gradle/
node_modules/
.env
*.pemStart from github/gitignore for your language, then add whatever this repository writes. Without one, git add . stages whatever the last build and the last terraform apply left in the tree, which is how a .env file and a private key end up on a remote in the first place.
More in secrets
secrets/detector-ran. A secret detector ran on the checkout, or left a report the build can be judged on, so something has actually looked for credentials.secrets/no-credential-files-committed. None of the well-known credential files is in the working tree: no.env, private key, keystore, kubeconfig or cloud credential file.secrets/no-hardcoded-credentials. Every secret the detector reported is below the severity the team gates on, or matches a rule the team has already accepted.