Skip to content

Test PR for verifying trufflehog#3559

Open
nikhil2611 wants to merge 1 commit into
mainfrom
nikhil/testing-trufflehog
Open

Test PR for verifying trufflehog#3559
nikhil2611 wants to merge 1 commit into
mainfrom
nikhil/testing-trufflehog

Conversation

@nikhil2611
Copy link
Copy Markdown
Contributor

Summary

This is a test PR to verify that the TruffleHog secret scanning is correctly configured and working in the chef-workstation CI pipeline.

Changes Made

  • Added .github/trufflehog-canary.env with intentionally fake canary credentials shaped like real GitHub tokens.

Expected Behavior

The TruffleHog CI job should flag the fake credentials as Found unverified Github result 🐷🔑, confirming secret scanning is active.

⚠️ Do not merge this PR. It is only for testing TruffleHog configuration. See inspec/inspec#7809 for reference.

Signed-off-by: nikhil2611 <ngupta@progress.com>
@nikhil2611 nikhil2611 requested a review from a team as a code owner May 20, 2026 07:07
Copilot AI review requested due to automatic review settings May 20, 2026 07:07
@nikhil2611 nikhil2611 requested review from a team as code owners May 20, 2026 07:07
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a canary .env file intended to validate that TruffleHog secret scanning is enabled and fails PRs when token-like secrets are detected.

Changes:

  • Added .github/trufflehog-canary.env containing intentionally fake values shaped like GitHub tokens to trigger TruffleHog findings.

Comment thread .github/trufflehog-canary.env
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants