ci: exclude test fixtures from secret detection and refresh commit-lint deps
What
Two bits of CI hygiene, both of which came out of triaging the vulnerability report.
ci— exclude test fixtures from secret detection.chore(deps)— refresh thecommit-lintlockfile.
Why
Secret detection was reporting its own test fixtures
The keypairs under internal/commands/auth/generate/testdata are generated by generate_test_keys.go in that same directory and used only by dpop_generate_test.go. Secret detection reported twelve of them as Critical.
Those are dismissed in the vulnerability report now. The exclusion stops each new fixture raising another, since per the documentation SECRET_DETECTION_EXCLUDED_PATHS only prevents future reports and does not retroactively clear existing ones.
Scoped to **/testdata/** rather than to all test files, so a credential committed into a _test.go is still caught.
Transitive npm dependencies never move
Dependency scanning reports seven High findings against js-yaml 4.1.0 and fast-uri 3.1.5. Both are transitive dependencies of @commitlint, which runs only in the lint_commit job against our own commit messages — nothing reaches a user and nothing ships in glab.
Renovate does cover this directory: npm is in enabledManagers and scripts/commit-lint is in includePaths. But it updates the direct @commitlint/* packages only, and the shared config sets lockFileMaintenance: { enabled: false, schedule: [] }, so a transitive dependency never moves unless a direct bump happens to drag it along.
npm update takes js-yaml to 4.3.2 and fast-uri to 3.1.8. Direct dependencies are unchanged.
Verification
npm auditreports 0 vulnerabilities after the update.commitlintstill acceptsfeat(ci): a valid messageand still rejects a subject with no type.glab ci lintvalid.
Notes for review
- The transitive gap is not npm-specific. Renovate's
gomodmanager likewise skips// indirectdependencies, which is whyx/imagesat at a September 2024 version. Two ecosystems, one blind spot — probably worth raising with therenovate-gitlab-botowners rather than patching it per repository. - Triage state for context: all 25 secret detection findings are now dismissed (16 as used in tests, 8 as false positive, 1 previously). What remains detected is 8 High dependency scanning — 7 of which this MR clears and 1 of which !3924 (merged) clears — plus 3 Medium dependency scanning and 38 SAST findings at Medium or Low.