Module continuous_delivery_scripts.update_secrets_registry

Record the project's accepted secret registry using detect-secrets.

Functions

def main() ‑> int
Expand source code
def main() -> int:
    """Script CLI."""
    parser = argparse.ArgumentParser(
        description=(
            "Record the project's accepted secret registry so allowed findings are not flagged again. "
            "This uses Yelp detect-secrets (https://github.com/Yelp/detect-secrets)."
        )
    )
    parser.add_argument(
        "-r",
        "--registry-file",
        default=_get_secrets_baseline_filename(),
        help="Secret registry file to generate.",
        type=Path,
    )
    parser.add_argument(
        "-v",
        "--verbose",
        action="count",
        default=0,
        help="Verbosity, by default errors are reported.",
    )
    args = parser.parse_args()
    set_log_level(args.verbose)

    try:
        update_secrets_registry(args.registry_file)
        return 0
    except Exception as e:
        log_exception(logger, e)
        return 1

Script CLI.

def update_secrets_registry(output_file: pathlib.Path | None = None) ‑> pathlib.Path
Expand source code
def update_secrets_registry(output_file: Optional[Path] = None) -> Path:
    """Record the project's accepted secret registry for detect-secrets."""
    project_root = Path(str(configuration.get_value(ConfigurationVariable.PROJECT_ROOT)))
    baseline_file = _get_secrets_baseline_file(output_file)
    logger.info("Updating secrets baseline at [%s].", baseline_file)
    baseline_contents = subprocess.check_output(
        _generate_detect_secrets_command_list(_determine_exclude_files()),
        cwd=str(project_root),
        encoding="utf8",
    )
    baseline_file.write_text(baseline_contents, encoding="utf8")
    return baseline_file

Record the project's accepted secret registry for detect-secrets.