Loading
Restrict new validity checks to GSS scanner findings
What does this MR do and why?
Restricts the new Secret Detection validity checks:
GitHub PATadded in !248110 (merged)OpenAI project keyadded in !248111 (merged)Anthropic API keyadded in !248112 (merged)Stripe live secret keyadded in !248114 (merged)Datadog API keyadded in !248115 (merged)SendGrid API tokenadded in !248116 (merged)Heroku API keyadded in !248117 (merged)
To findings whose identifiers include the GitLab Secret Scanning for Source Code (GSS) rule identifier types:
gitlab_secret_scanner_rule_id(current one)gitlab_secrets_scanner_rule_id(older, used before the analyzer's v0.16.0 rename).
Findings from the gitleaks-based analyzer will not have a validity status for these token types.
Slack (!248113 (closed)) stays parked due to structure inconsistency.
The new restricted_to_gss_scanner attribute is added to both:
Security::SecretDetection::PartnerTokens::Registry:truefor the new checks,falsefor the pre-existing ones.Security::SecretDetection::TokenLookupService:falsefor all current GitLab token types, so future checks can opt in.
Resolves #612117 (closed).
MR acceptance checklist
I have evaluated this MR against the MR acceptance checklist.
Edited by Ahmed Hemdan