secret-guard: no live credentials in bridged repos (hash-only findings)
All checks were successful
check / gate (push) Successful in 22s
All checks were successful
check / gate (push) Successful in 22s
New guard windy-git/secret-guard (warn-only) over EVERY text file: Telegram, GitHub, AWS, Slack, Anthropic, OpenAI, Stripe live, Google API keys and private-key blocks (scripts/secret_shapes.py, shared with the weekly public scan). A finding carries "<kind> #<sha256[:8]>", never the value (house rule 10). Known fakes allowed BY HASH (ci/secret-guard-allow.yml). GUARDS_STATUS gets a secrets column. Leak hunt 09-24: @Windy_0_bot token in a public fixture. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -372,6 +372,7 @@ def post_statuses(repo: str, sha: str) -> None:
|
||||
|
||||
GUARD_CTX = "windy-git/compute-guard"
|
||||
HYGIENE_CTX = "windy-git/ci-hygiene"
|
||||
SECRET_CTX = "windy-git/secret-guard"
|
||||
|
||||
|
||||
def post_compute_guard(repo: str, sha: str, default_branch: str, is_default_head: bool) -> None:
|
||||
@@ -379,6 +380,11 @@ def post_compute_guard(repo: str, sha: str, default_branch: str, is_default_head
|
||||
_post_guard("compute_guard", GUARD_CTX, repo, sha, default_branch, is_default_head)
|
||||
|
||||
|
||||
def post_secret_guard(repo: str, sha: str, default_branch: str, is_default_head: bool) -> None:
|
||||
"""No live credential in a bridged repo (leak hunt 09-24). Findings carry sha256[:8] only."""
|
||||
_post_guard("secret_guard", SECRET_CTX, repo, sha, default_branch, is_default_head)
|
||||
|
||||
|
||||
def post_ci_hygiene(repo: str, sha: str, default_branch: str, is_default_head: bool) -> None:
|
||||
"""House rule 6: lockfile-only installs, pinned images, no host-port services (warn-only)."""
|
||||
_post_guard("ci_hygiene", HYGIENE_CTX, repo, sha, default_branch, is_default_head)
|
||||
@@ -438,6 +444,7 @@ def main() -> int:
|
||||
post_statuses(repo, sha)
|
||||
post_compute_guard(repo, sha, default_branch, sha == default_head)
|
||||
post_ci_hygiene(repo, sha, default_branch, sha == default_head)
|
||||
post_secret_guard(repo, sha, default_branch, sha == default_head)
|
||||
except Exception as e: # one repo's failure must not hide the others'
|
||||
print(f" FAILED {repo}: {e}")
|
||||
failed = 1
|
||||
|
||||
Reference in New Issue
Block a user