elastic / package-spec

EPR package specifications
Other
17 stars 70 forks source link

Discard variables ending with _file or _url as secret candidates #712

Closed jsoriano closed 7 months ago

jsoriano commented 7 months ago

What does this PR do?

Disable variables ending with _file or _url as secret candidates.

Why is it important?

Reduce the number of false positives. Variables with potential secrets with these names use to refer to files that contain secrets, and not to secrets themselves.

Checklist

Related issues

jsoriano commented 7 months ago

Excluding also variables ending with _url.

elasticmachine commented 7 months ago

:green_heart: Build Succeeded

History

cc @jsoriano