-
Notifications
You must be signed in to change notification settings - Fork 3.3k
{CI} Suppress false positives in Credential Scanner #32669
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
️✔️AzureCLI-FullTest
|
|
Hi @necusjz, |
️✔️AzureCLI-BreakingChangeTest
|
|
Thank you for your contribution! We will review the pull request and get back to you soon. |
|
The git hooks are available for azure-cli and azure-cli-extensions repos. They could help you run required checks before creating the PR. Please sync the latest code with latest dev branch (for azure-cli) or main branch (for azure-cli-extensions). pip install azdev --upgrade
azdev setup -c <your azure-cli repo path> -r <your azure-cli-extensions repo path>
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
This PR suppresses two false positive credential scanner alerts that were blocking CI builds. The credential scanner incorrectly flagged benign code patterns as potential security issues.
Changes:
- Added suppression for PostgreSQL module's
flexible_server_custom_postgres.pywhich uses placeholder strings like'<user>'and'<password>'in output messages - Added suppression for Network module's test file
test_network_commands.pywhich uses a hardcoded test password for certificate generation in tests
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Related command
Description
from https://dev.azure.com/azclitools/public/_build/results?buildId=291659&view=logs&jobId=9a50307c-53e6-51fa-ddad-d8767a4a0ece&j=9a50307c-53e6-51fa-ddad-d8767a4a0ece&t=51a28232-c495-58b8-0a15-8a556d230675:
Both
azure-cli/src/azure-cli/azure/cli/command_modules/postgresql/flexible_server_custom_postgres.py
Line 211 in aeee555
and
azure-cli/src/azure-cli/azure/cli/command_modules/network/tests/latest/test_network_commands.py
Line 6256 in 47cfdec
don't have any secret. They're false positives.
Testing Guide
History Notes
[Component Name 1] BREAKING CHANGE:
az command a: Make some customer-facing breaking change[Component Name 2]
az command b: Add some customer-facing featureThis checklist is used to make sure that common guidelines for a pull request are followed.
The PR title and description has followed the guideline in Submitting Pull Requests.
I adhere to the Command Guidelines.
I adhere to the Error Handling Guidelines.