-
Notifications
You must be signed in to change notification settings - Fork 1.8k
[None][infra] add nspect allow list for false positive secrets #5797
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[None][infra] add nspect allow list for false positive secrets #5797
Conversation
|
@yuanjingx87 , do we still need this on |
I think better if we can, but should not blocking the release, those are all false positive secrets that are reported by nspect |
|
@yuanjingx87 , please move this to |
387af53 to
baed626
Compare
📝 WalkthroughWalkthroughA new Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Note ⚡️ Unit Test Generation is now available in beta!Learn more here, or try it out under "Finishing Touches" below. 📜 Recent review detailsConfiguration used: .coderabbit.yaml 📒 Files selected for processing (1)
✅ Files skipped from review due to trivial changes (1)
✨ Finishing Touches🧪 Generate unit tests
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
Documentation and Community
|
|
@MartinMarciniszyn Just targeted main for this PR |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 1
♻️ Duplicate comments (1)
.nspect-allowlist.toml (1)
1-1: Avoid referencing internal Confluence in repo-resident configs
The link to the internal Confluence page is inaccessible to external contributors and automated tooling and should be removed or replaced with public documentation.
🧹 Nitpick comments (1)
.nspect-allowlist.toml (1)
19-22: Masked value includes a trailing quote – verify intent
The masked secret ends withASS"(including the quote). If the quote is not part of the literal string in the Groovy script, the pattern will not match and the secret will still be flagged. Double-check whether the quote is required.
📜 Review details
Configuration used: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (1)
.nspect-allowlist.toml(1 hunks)
🔇 Additional comments (1)
.nspect-allowlist.toml (1)
65-70: Verify presence and spelling of the WindowsTest Groovy file
I wasn’t able to locate eitherjenkins/L0_L1_Nighty_WindowsTest.groovyor a correctly spelledjenkins/L0_L1_Nightly_WindowsTest.groovyin the repo. Please:
- Confirm that the file actually exists under the
jenkins/directory- Verify whether its name is “Nighty” or “Nightly”
- If it should be “Nightly,” update your
.nspect-allowlist.tomlaccordingly:- file = "jenkins/L0_L1_Nighty_WindowsTest.groovy" + file = "jenkins/L0_L1_Nightly_WindowsTest.groovy"
baed626 to
bf4c0f1
Compare
|
/bot run --disable-fast-fail |
|
PR_Github #14112 Bot args parsing error: usage: /bot [-h] |
|
/bot run --disable-fail-fast |
|
PR_Github #14177 [ run ] triggered by Bot |
|
PR_Github #14177 [ run ] completed with state |
Signed-off-by: Yuanjing Xue <197832395+yuanjingx87@users.noreply.github.com>
bf4c0f1 to
4fc47cd
Compare
|
/bot reuse-pipeline |
|
PR_Github #18823 [ reuse-pipeline ] triggered by Bot |
|
PR_Github #18823 [ reuse-pipeline ] completed with state |
|
/bot skip --comment "No need to run CI" |
|
PR_Github #18825 [ skip ] triggered by Bot |
|
PR_Github #18825 [ skip ] completed with state |
Signed-off-by: Yuanjing Xue <197832395+yuanjingx87@users.noreply.github.com>
…A#5797) Signed-off-by: Yuanjing Xue <197832395+yuanjingx87@users.noreply.github.com>
…A#5797) Signed-off-by: Yuanjing Xue <197832395+yuanjingx87@users.noreply.github.com>
[security] add nspce allow list for false positive secrets
Description
We have some secrets that are reported, but those are all false positive, so I add them to the allowed list.
Test Coverage
GitHub Bot Help
/bot [-h] ['run', 'kill', 'skip', 'reuse-pipeline'] ...Provide a user friendly way for developers to interact with a Jenkins server.
Run
/bot [-h|--help]to print this help message.See details below for each supported subcommand.
run [--disable-fail-fast --skip-test --stage-list "A10-1, xxx" --gpu-type "A30, H100_PCIe" --add-multi-gpu-test --only-multi-gpu-test --disable-multi-gpu-test --post-merge --extra-stage "H100_PCIe-[Post-Merge]-1, xxx"]Launch build/test pipelines. All previously running jobs will be killed.
--disable-fail-fast(OPTIONAL) : Disable fail fast on build/tests/infra failures.--skip-test(OPTIONAL) : Skip all test stages, but still run build stages, package stages and sanity check stages. Note: Does NOT update GitHub check status.--stage-list "A10-1, xxx"(OPTIONAL) : Only run the specified test stages. Examples: "A10-1, xxx". Note: Does NOT update GitHub check status.--gpu-type "A30, H100_PCIe"(OPTIONAL) : Only run the test stages on the specified GPU types. Examples: "A30, H100_PCIe". Note: Does NOT update GitHub check status.--only-multi-gpu-test(OPTIONAL) : Only run the multi-GPU tests. Note: Does NOT update GitHub check status.--disable-multi-gpu-test(OPTIONAL) : Disable the multi-GPU tests. Note: Does NOT update GitHub check status.--add-multi-gpu-test(OPTIONAL) : Force run the multi-GPU tests. Will also run L0 pre-merge pipeline.--post-merge(OPTIONAL) : Run the L0 post-merge pipeline instead of the ordinary L0 pre-merge pipeline.--extra-stage "H100_PCIe-[Post-Merge]-1, xxx"(OPTIONAL) : Run the ordinary L0 pre-merge pipeline and specified test stages. Examples: --extra-stage "H100_PCIe-[Post-Merge]-1, xxx".For guidance on mapping tests to stage names, see
docs/source/reference/ci-overview.md.kill
killKill all running builds associated with pull request.
skip
skip --comment COMMENTSkip testing for latest commit on pull request.
--comment "Reason for skipping build/test"is required. IMPORTANT NOTE: This is dangerous since lack of user care and validation can cause top of tree to break.reuse-pipeline
reuse-pipelineReuse a previous pipeline to validate current commit. This action will also kill all currently running builds associated with the pull request. IMPORTANT NOTE: This is dangerous since lack of user care and validation can cause top of tree to break.
Summary by CodeRabbit