KEMBAR78
[None][infra] add nspect allow list for false positive secrets by yuanjingx87 · Pull Request #5797 · NVIDIA/TensorRT-LLM · GitHub
Skip to content

Conversation

@yuanjingx87
Copy link
Collaborator

@yuanjingx87 yuanjingx87 commented Jul 7, 2025

[security] add nspce allow list for false positive secrets

Description

We have some secrets that are reported, but those are all false positive, so I add them to the allowed list.

Test Coverage

GitHub Bot Help

/bot [-h] ['run', 'kill', 'skip', 'reuse-pipeline'] ...

Provide a user friendly way for developers to interact with a Jenkins server.

Run /bot [-h|--help] to print this help message.

See details below for each supported subcommand.

run [--disable-fail-fast --skip-test --stage-list "A10-1, xxx" --gpu-type "A30, H100_PCIe" --add-multi-gpu-test --only-multi-gpu-test --disable-multi-gpu-test --post-merge --extra-stage "H100_PCIe-[Post-Merge]-1, xxx"]

Launch build/test pipelines. All previously running jobs will be killed.

--disable-fail-fast (OPTIONAL) : Disable fail fast on build/tests/infra failures.

--skip-test (OPTIONAL) : Skip all test stages, but still run build stages, package stages and sanity check stages. Note: Does NOT update GitHub check status.

--stage-list "A10-1, xxx" (OPTIONAL) : Only run the specified test stages. Examples: "A10-1, xxx". Note: Does NOT update GitHub check status.

--gpu-type "A30, H100_PCIe" (OPTIONAL) : Only run the test stages on the specified GPU types. Examples: "A30, H100_PCIe". Note: Does NOT update GitHub check status.

--only-multi-gpu-test (OPTIONAL) : Only run the multi-GPU tests. Note: Does NOT update GitHub check status.

--disable-multi-gpu-test (OPTIONAL) : Disable the multi-GPU tests. Note: Does NOT update GitHub check status.

--add-multi-gpu-test (OPTIONAL) : Force run the multi-GPU tests. Will also run L0 pre-merge pipeline.

--post-merge (OPTIONAL) : Run the L0 post-merge pipeline instead of the ordinary L0 pre-merge pipeline.

--extra-stage "H100_PCIe-[Post-Merge]-1, xxx" (OPTIONAL) : Run the ordinary L0 pre-merge pipeline and specified test stages. Examples: --extra-stage "H100_PCIe-[Post-Merge]-1, xxx".

For guidance on mapping tests to stage names, see docs/source/reference/ci-overview.md.

kill

kill

Kill all running builds associated with pull request.

skip

skip --comment COMMENT

Skip testing for latest commit on pull request. --comment "Reason for skipping build/test" is required. IMPORTANT NOTE: This is dangerous since lack of user care and validation can cause top of tree to break.

reuse-pipeline

reuse-pipeline

Reuse a previous pipeline to validate current commit. This action will also kill all currently running builds associated with the pull request. IMPORTANT NOTE: This is dangerous since lack of user care and validation can cause top of tree to break.

Summary by CodeRabbit

  • Chores
    • Added a configuration file to allow specific masked secrets in Jenkins scripts to be ignored during automated secrets scanning.

@yuanjingx87 yuanjingx87 requested a review from a team as a code owner July 7, 2025 14:01
@yuanjingx87 yuanjingx87 changed the title add nspce allow list for false positive secrets [security] add nspce allow list for false positive secrets Jul 7, 2025
@MartinMarciniszyn
Copy link
Collaborator

@yuanjingx87 , do we still need this on release/0.21?

@yuanjingx87
Copy link
Collaborator Author

@yuanjingx87 , do we still need this on release/0.21?

I think better if we can, but should not blocking the release, those are all false positive secrets that are reported by nspect

@MartinMarciniszyn
Copy link
Collaborator

@yuanjingx87 , please move this to main.

@yuanjingx87 yuanjingx87 force-pushed the user/yuanjingx/add_allowlist_for_secret_scanning branch from 387af53 to baed626 Compare August 5, 2025 07:09
@coderabbitai
Copy link
Contributor

coderabbitai bot commented Aug 5, 2025

📝 Walkthrough

Walkthrough

A new .nspect-allowlist.toml configuration file has been introduced to define an allowlist for secrets scanning. This file specifies certain Jenkins Groovy script files and lists masked secret patterns to be ignored by Pulse Trufflehog during scanning.

Changes

Cohort / File(s) Change Summary
Secrets Allowlist Configuration
.nspect-allowlist.toml
Added a TOML configuration file specifying version, targeted Jenkins Groovy script files, and allowed masked secrets for Pulse Trufflehog scanning.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Note

⚡️ Unit Test Generation is now available in beta!

Learn more here, or try it out under "Finishing Touches" below.


📜 Recent review details

Configuration used: .coderabbit.yaml
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between baed626 and bf4c0f1.

📒 Files selected for processing (1)
  • .nspect-allowlist.toml (1 hunks)
✅ Files skipped from review due to trivial changes (1)
  • .nspect-allowlist.toml
✨ Finishing Touches
🧪 Generate unit tests
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Explain this complex logic.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai explain this code block.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and explain its main purpose.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate docstrings to generate docstrings for this PR.
  • @coderabbitai generate sequence diagram to generate a sequence diagram of the changes in this PR.
  • @coderabbitai generate unit tests to generate unit tests for this PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai or @coderabbitai title anywhere in the PR title to generate the title automatically.

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@yuanjingx87 yuanjingx87 changed the base branch from release/0.21 to main August 5, 2025 07:09
@yuanjingx87
Copy link
Collaborator Author

@MartinMarciniszyn Just targeted main for this PR

Copy link
Contributor

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

♻️ Duplicate comments (1)
.nspect-allowlist.toml (1)

1-1: Avoid referencing internal Confluence in repo-resident configs
The link to the internal Confluence page is inaccessible to external contributors and automated tooling and should be removed or replaced with public documentation.

🧹 Nitpick comments (1)
.nspect-allowlist.toml (1)

19-22: Masked value includes a trailing quote – verify intent
The masked secret ends with ASS" (including the quote). If the quote is not part of the literal string in the Groovy script, the pattern will not match and the secret will still be flagged. Double-check whether the quote is required.

📜 Review details

Configuration used: .coderabbit.yaml
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 4d040b5 and baed626.

📒 Files selected for processing (1)
  • .nspect-allowlist.toml (1 hunks)
🔇 Additional comments (1)
.nspect-allowlist.toml (1)

65-70: Verify presence and spelling of the WindowsTest Groovy file
I wasn’t able to locate either jenkins/L0_L1_Nighty_WindowsTest.groovy or a correctly spelled jenkins/L0_L1_Nightly_WindowsTest.groovy in the repo. Please:

  • Confirm that the file actually exists under the jenkins/ directory
  • Verify whether its name is “Nighty” or “Nightly”
  • If it should be “Nightly,” update your .nspect-allowlist.toml accordingly:
    - file = "jenkins/L0_L1_Nighty_WindowsTest.groovy"
    + file = "jenkins/L0_L1_Nightly_WindowsTest.groovy"

@yuanjingx87 yuanjingx87 force-pushed the user/yuanjingx/add_allowlist_for_secret_scanning branch from baed626 to bf4c0f1 Compare August 5, 2025 07:35
@yuanjingx87
Copy link
Collaborator Author

/bot run --disable-fast-fail

@yuanjingx87 yuanjingx87 changed the title [security] add nspce allow list for false positive secrets [None][infra] add nspce allow list for false positive secrets Aug 5, 2025
@tensorrt-cicd
Copy link
Collaborator

PR_Github #14112 Bot args parsing error: usage: /bot [-h]
{run,kill,skip,submit,reviewers,reuse-pipeline,reuse-review} ...
/bot: error: unrecognized arguments: --disable-fast-fail

@yuanjingx87
Copy link
Collaborator Author

/bot run --disable-fail-fast

@tensorrt-cicd
Copy link
Collaborator

PR_Github #14177 [ run ] triggered by Bot

@tensorrt-cicd
Copy link
Collaborator

PR_Github #14177 [ run ] completed with state SUCCESS
/LLM/main/L0_MergeRequest_PR pipeline #10702 completed with status: 'SUCCESS'
Pipeline passed with automatic retried tests. Check the rerun report for details.

Signed-off-by: Yuanjing Xue <197832395+yuanjingx87@users.noreply.github.com>
@yuanjingx87 yuanjingx87 force-pushed the user/yuanjingx/add_allowlist_for_secret_scanning branch from bf4c0f1 to 4fc47cd Compare September 16, 2025 19:19
@yuanjingx87 yuanjingx87 changed the title [None][infra] add nspce allow list for false positive secrets [None][infra] add nspct allow list for false positive secrets Sep 16, 2025
@yuanjingx87 yuanjingx87 changed the title [None][infra] add nspct allow list for false positive secrets [None][infra] add nspect allow list for false positive secrets Sep 16, 2025
@yuanjingx87
Copy link
Collaborator Author

/bot reuse-pipeline

@tensorrt-cicd
Copy link
Collaborator

PR_Github #18823 [ reuse-pipeline ] triggered by Bot

@tensorrt-cicd
Copy link
Collaborator

PR_Github #18823 [ reuse-pipeline ] completed with state SUCCESS
Can't reuse PR_Github #0 with status: UNKNOWN

@yuanjingx87
Copy link
Collaborator Author

/bot skip --comment "No need to run CI"

@tensorrt-cicd
Copy link
Collaborator

PR_Github #18825 [ skip ] triggered by Bot

@tensorrt-cicd
Copy link
Collaborator

PR_Github #18825 [ skip ] completed with state SUCCESS
Skipping testing for commit 4fc47cd

@yuanjingx87 yuanjingx87 merged commit 0f30d7d into NVIDIA:main Sep 16, 2025
9 checks passed
yuanjingx87 added a commit that referenced this pull request Sep 17, 2025
Signed-off-by: Yuanjing Xue <197832395+yuanjingx87@users.noreply.github.com>
Wong4j pushed a commit to Wong4j/TensorRT-LLM that referenced this pull request Sep 20, 2025
…A#5797)

Signed-off-by: Yuanjing Xue <197832395+yuanjingx87@users.noreply.github.com>
MrGeva pushed a commit to nv-auto-deploy/TensorRT-LLM that referenced this pull request Sep 21, 2025
…A#5797)

Signed-off-by: Yuanjing Xue <197832395+yuanjingx87@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants