Skip to content

Update CredScanSuppressions.json#43497

Merged
dougbu merged 1 commit intorelease/7.0from
brecon/cred2
Aug 24, 2022
Merged

Update CredScanSuppressions.json#43497
dougbu merged 1 commit intorelease/7.0from
brecon/cred2

Conversation

@BrennanConroy
Copy link
Copy Markdown
Member

Moved the certs to a shared location for other SignalR tests in another PR, forgot about this file.

@BrennanConroy BrennanConroy requested review from a team, dougbu and wtgodbe as code owners August 23, 2022 21:03
@BrennanConroy BrennanConroy requested a review from Pilchie August 23, 2022 21:03
@ghost ghost added the area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework label Aug 23, 2022
Copy link
Copy Markdown
Contributor

@dougbu dougbu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Surprised I'm not getting code-mirror failure emails but agree this is necessary.

@dougbu
Copy link
Copy Markdown
Contributor

dougbu commented Aug 23, 2022

Any reason I shouldn't set auto-squish @BrennanConroy

@BrennanConroy
Copy link
Copy Markdown
Member Author

Go for it

@dougbu
Copy link
Copy Markdown
Contributor

dougbu commented Aug 23, 2022

Oddly, I can't for some reason. Thought I'd done this elsewhere in release/7.0 but maybe not… Same for you @wtgodbe

@BrennanConroy
Copy link
Copy Markdown
Member Author

It looks like it'll let me Squash and merge without waiting for builds. There aren't any required pipelines for release/7.0

@dougbu dougbu enabled auto-merge (squash) August 23, 2022 21:33
@dougbu
Copy link
Copy Markdown
Contributor

dougbu commented Aug 23, 2022

Ah, it was my bad. I changed the branch protection rules in order to clean up a couple of old branches. Forgot to reset protections ☹️. All is well now and auto-merge (squash) is set to go.

@dougbu dougbu merged commit 21794e1 into release/7.0 Aug 24, 2022
@dougbu dougbu deleted the brecon/cred2 branch August 24, 2022 04:29
@BrennanConroy BrennanConroy added this to the 7.0-rc2 milestone Aug 24, 2022
@dougbu
Copy link
Copy Markdown
Contributor

dougbu commented Aug 26, 2022

Does this need to be backported to the rc1 branch @BrennanConroy

@BrennanConroy
Copy link
Copy Markdown
Member Author

Why? That branch is temporary. Do we really care about CG alerts for it when we know they're going away soon?

@Pilchie
Copy link
Copy Markdown
Member

Pilchie commented Aug 26, 2022

Given these are just suppressions and not real credential issues, I'm not worried about causing more churn in the rc1 branch for this.

@BrennanConroy
Copy link
Copy Markdown
Member Author

That comment can be interpreted either way 😆, yes or no to backporting to release/7.0-rc1?

@Pilchie
Copy link
Copy Markdown
Member

Pilchie commented Aug 26, 2022

Sorry - no need to backport to release/7.0-rc1.

@dougbu
Copy link
Copy Markdown
Contributor

dougbu commented Aug 26, 2022

Why?

Sorry it was an actual question, not a statement of a requirement. I was wondering if the files had been renamed in RC1 w/o this update because that would cause build breaks IIRC.

@BrennanConroy
Copy link
Copy Markdown
Member Author

The files were renamed in RC1, the suppressions have been updated in RC2 and main.

What build breaks would not having the suppression cause?

@dougbu
Copy link
Copy Markdown
Contributor

dougbu commented Aug 26, 2022

Not exactly "build breaks". The missing suppression should cause CredScan errors and issues filed against us and that we need to handle for RC1. If @Pilchie is fine dismissing the issues, we're good.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants