diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 7f0315c..bb2ebbd 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -18,10 +18,11 @@ jobs: fetch-depth: 0 - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: - go-version: '1.26.8' + # Fixes timed-fuzz cancellation failures: https://go.dev/issue/75804. + go-version: '1.27.1' - run: go run golang.org/x/vuln/cmd/govulncheck@v1.6.0 ./... - name: Redacted history secret scan - run: go run github.com/zricethezav/gitleaks/v8@v8.30.1 git --redact --log-opts=--all --no-banner . + run: go run github.com/zricethezav/gitleaks/v8@v8.30.1 git --redact=100 --verbose --log-opts=--all --no-banner . - name: Extended malformed-input testing run: | go test ./internal/compare -run '^$' -fuzz '^FuzzCanonicalSummary$' -fuzztime 2m -parallel 2 diff --git a/.gitleaksignore b/.gitleaksignore new file mode 100644 index 0000000..35c4919 --- /dev/null +++ b/.gitleaksignore @@ -0,0 +1,12 @@ +# SPDX-License-Identifier: Apache-2.0 +# Code authors: Vijay and Codex +# Reviewed synthetic test data only. Each exception is bound to one commit, +# file, rule, and line; new occurrences still require review. + +# Dummy hashing secret used only by the isolated collector config validator. +b214e8466291879aa7862f7d26875778ee20ea95:.github/workflows/ci.yml:generic-api-key:61 +b214e8466291879aa7862f7d26875778ee20ea95:internal/diagnose/shadow_test.go:generic-api-key:43 + +# Planted sentinels asserting that CLI and config input never enters reports. +b214e8466291879aa7862f7d26875778ee20ea95:internal/cli/diagnose_test.go:generic-api-key:85 +b214e8466291879aa7862f7d26875778ee20ea95:internal/diagnose/diagnose_test.go:generic-api-key:65