Skip to content

[Backport] Pipeline upload: look for secrets within trigger step build.env - #4189

Open
DrJosh9000 wants to merge 1 commit into
v3from
backport-pr-4116-to-v3
Open

[Backport] Pipeline upload: look for secrets within trigger step build.env#4189
DrJosh9000 wants to merge 1 commit into
v3from
backport-pr-4116-to-v3

Conversation

@DrJosh9000

@DrJosh9000 DrJosh9000 commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Copy of #4116 description below. I'm not fully decided whether this backport is worth it.


Description

Trigger steps can contain env blocks too: under build. In pipeline upload, include these in the secret search.

Context

Buildsworth outputted some tokens upon the v4 branch: #3807 (comment)

Testing

  • Tests have run locally (with go test ./...). Buildkite employees may check this if the pipeline has run automatically.
  • Code is formatted (with go tool gofumpt -extra -w .)

Disclosures / Credits

I happen to know how this works.

@DrJosh9000
DrJosh9000 requested review from a team as code owners August 6, 2026 07:00
@DrJosh9000
DrJosh9000 enabled auto-merge August 6, 2026 07:00
@DrJosh9000 DrJosh9000 added the bug label Aug 6, 2026

@buildsworth-bk-app buildsworth-bk-app Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found in this pass. This changes pipeline-upload secret detection, so I’m leaving final approval to a human reviewer. The agent CI check is still pending.

Want to dig deeper?

Paste this into your agent to explore the findings from this review's Buildkite build:

Download the buildsworth logs from build 12440, then answer my questions about the findings.

Install the reading-buildsworth-logs skill to run this.

About buildsworth

Model: gpt-5.6-sol with xhigh thinking.

How to request a review: Comment @buildsworth-bk review on the PR, or request buildsworth-bk as a reviewer.

Risk labels (how buildsworth classifies risk) — buildsworth classifies risk itself from the diff. To let it approve, grant L2 approval by mentioning @buildsworth-bk (see L2 approval grant):

  • L1 — Low risk (dep bumps, docs/copy, lockfiles, small presentational fixes). buildsworth may approve by default.
  • L2 — Standard risk (new UI, additive API fields, refactors). Approved only with an L2 grant; otherwise comment-only.
  • L3 — High risk (auth, migrations, payments, secrets, perf-critical paths). Human review always required.

@DrJosh9000
DrJosh9000 disabled auto-merge August 6, 2026 07:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant