fix(ci): harden diffs viewer request guard and secret scan baseline

This commit is contained in:
Peter Steinberger
2026-03-07 17:31:24 +00:00
parent 8e20dd22d8
commit 630485ac98
2 changed files with 7 additions and 7 deletions

View File

@@ -38,7 +38,7 @@ def maybe_decode_hex_keychain_secret(value)
# `security find-generic-password -w` can return hex when the stored secret
# includes newlines/non-printable bytes (like PEM files).
if decoded.include?("BEGIN PRIVATE KEY") || decoded.include?("END PRIVATE KEY")
if decoded.include?("BEGIN PRIVATE KEY") || decoded.include?("END PRIVATE KEY") # pragma: allowlist secret
UI.message("Decoded hex-encoded ASC key content from Keychain.")
return decoded
end