⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.
Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.
🔎 Detected hardcoded secret in your pull request
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
| -------------- | ------------------ | ------------------------------ | ---------------- | --------------- | -------------------- |
| [-](https://dashboard.gitguardian.com/workspace/265002/incidents/secrets) | | Generic Password | 9e9c6b992babc21714d511dac9ee8887920bd1c6 | connection.json | [View secret](https://github.com/Snowflake-Labs/sfguide-getting-started-dataengineering-ml-snowpark-python/commit/9e9c6b992babc21714d511dac9ee8887920bd1c6#diff-d8b3cf8aaf77d1fa21cd53f3cafa4b6e28a33b1ec1b79997b9aa3c8d484b566fL4) |
🛠 Guidelines to remediate hardcoded secrets
The above secret(s) have been detected in your PR. Please take an appropriate action for each secret:
- If it’s a **true positive**, remove the secret from source code, revoke it and migrate to a secure way of storing and accessing secrets (see http://go/secrets-and-code). Once that’s done, go to the incidents page linked in the “GitGuardian id” column (log in using SnowBiz Okta) and resolve the incident.
- If it’s a **false positive**, go to the incidents page linked in the “GitGuardian id” column (log in using SnowBiz Okta) and ignore the incident.
- If you didn't add this secret - and only then - you may ignore this check as it's non-blocking. If you *did* add the secret and you ignore this check, you'll be assigned a "Security Finding" ticket in Jira in a few days.
Note:
- **A secret is considered leaked from the moment it touches GitHub.** Rewriting git history by force pushing or other means is not necessary and doesn’t change the fact that the secret has to be revoked.
- This check has a “Skip: false positive” button. **Don’t use it.** It will mark all detected secrets as false positives but only in the context of this specific run - it won’t remember this action in subsequent check runs.
If you encounter any problems you can reach out to us on Slack: #gitguardian-secret-scanning-help
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.
Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.
🔎 Detected hardcoded secret in your pull request
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | | | -------------- | ------------------ | ------------------------------ | ---------------- | --------------- | -------------------- | | [-](https://dashboard.gitguardian.com/workspace/265002/incidents/secrets) | | Generic Password | 9e9c6b992babc21714d511dac9ee8887920bd1c6 | connection.json | [View secret](https://github.com/Snowflake-Labs/sfguide-getting-started-dataengineering-ml-snowpark-python/commit/9e9c6b992babc21714d511dac9ee8887920bd1c6#diff-d8b3cf8aaf77d1fa21cd53f3cafa4b6e28a33b1ec1b79997b9aa3c8d484b566fL4) |
🛠 Guidelines to remediate hardcoded secrets
The above secret(s) have been detected in your PR. Please take an appropriate action for each secret: - If it’s a **true positive**, remove the secret from source code, revoke it and migrate to a secure way of storing and accessing secrets (see http://go/secrets-and-code). Once that’s done, go to the incidents page linked in the “GitGuardian id” column (log in using SnowBiz Okta) and resolve the incident. - If it’s a **false positive**, go to the incidents page linked in the “GitGuardian id” column (log in using SnowBiz Okta) and ignore the incident. - If you didn't add this secret - and only then - you may ignore this check as it's non-blocking. If you *did* add the secret and you ignore this check, you'll be assigned a "Security Finding" ticket in Jira in a few days. Note: - **A secret is considered leaked from the moment it touches GitHub.** Rewriting git history by force pushing or other means is not necessary and doesn’t change the fact that the secret has to be revoked. - This check has a “Skip: false positive” button. **Don’t use it.** It will mark all detected secrets as false positives but only in the context of this specific run - it won’t remember this action in subsequent check runs. If you encounter any problems you can reach out to us on Slack: #gitguardian-secret-scanning-help
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.