Skip to content

Guardrails / secrets

Repository ignores what it must not commit ​

secrets/gitignore-present@v1

The repository has a .gitignore, so the next person who runs git add . doesn't commit build output or the local credential files next to it.

Idsecrets/gitignore-present
Versionv1
Categorysecrets
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsfiles

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
filesPresence, size and line counts of the well known files a repository is expected to carry, plus any extra path the guardrail asks for.path

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "secrets/gitignore-present@v1",
              "severity": "warning",
              "with": {
                  "path": ".gitignore",
                  "minLines": "1"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
pathPath to the ignore file, relative to the directory the CLI runs in..gitignoreGUARDRAIL_INPUT_PATH
minLinesFewest non-blank lines the file must have to count as written.1GUARDRAIL_INPUT_MINLINES

How to fix ​

Add a .gitignore at the repository root that covers build output and local configuration:

build/
.gradle/
node_modules/
.env
*.pem

Start from github/gitignore for your language, then add whatever this repository writes. Without one, git add . stages whatever the last build and the last terraform apply left in the tree, which is how a .env file and a private key end up on a remote in the first place.

More in secrets ​

  • secrets/detector-ran. A secret detector ran on the checkout, or left a report the build can be judged on, so something has actually looked for credentials.
  • secrets/no-credential-files-committed. None of the well-known credential files is in the working tree: no .env, private key, keystore, kubeconfig or cloud credential file.
  • secrets/no-hardcoded-credentials. Every secret the detector reported is below the severity the team gates on, or matches a rule the team has already accepted.

All 4 secrets guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412