Record accepted secret-scan findings
Problem and when to use it
Accidentally committing passwords, API keys or tokens to a Git repository can
expose them to anyone with access to the repository and its history. Even if
the file is later deleted, the secret may already have leaked. Use
cd-detect-secrets to catch new findings before
they are committed or merged.
cd-record-secrets maintains the detect-secrets baseline used by that check.
Run it only after reviewing findings to record known, acceptable values
that would otherwise be reported again. Do not add a real secret to the
baseline to silence the check; if one was committed, remove it and rotate the
credential.
Inputs and example
Run from a configured project with detect-secrets installed. The registry
path defaults to SECRETS_BASELINE_FILENAME and can be overridden:
cd-record-secrets --registry-file .secrets.baseline
The project plugin supplies exclusion patterns for generated or unsuitable files. Review the diff before committing the registry.
Output
An updated secret-registry file in the project checkout. Use
cd-detect-secrets to check tracked files against
it in CI.
GitHub Actions example
For a reviewed baseline refresh, after checkout and installation:
- run: cd-record-secrets --registry-file .secrets.baseline
- run: git diff -- .secrets.baseline
Commit the change only after reviewing accepted findings.