Skip to content

Disable secrets-outside-env audit#2969

Merged
martincostello merged 1 commit into
mainfrom
disable-secrets-outside-env
Mar 9, 2026
Merged

Disable secrets-outside-env audit#2969
martincostello merged 1 commit into
mainfrom
disable-secrets-outside-env

Conversation

@martincostello

Copy link
Copy Markdown
Member

This isn't appropriate in most cases as there's no logical environment, and environments are already used in cases where they are.

This isn't appropriate in most cases as there's no logical environment, and environments are already used in cases where they are.
Copilot AI review requested due to automatic review settings March 9, 2026 11:32
@martincostello martincostello enabled auto-merge (squash) March 9, 2026 11:32

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR disables the secrets-outside-env zizmor audit rule in the project's CI security linting configuration. The repository uses GitHub Actions secrets in many workflows where GitHub Environments don't logically apply (e.g., Codecov tokens, bot app credentials), and environments are already used where they make sense (Azure signing, NuGet publishing).

Changes:

  • Added secrets-outside-env: disable: true to the zizmor configuration file to suppress false positives from this audit rule.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@codecov

codecov Bot commented Mar 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 96.15%. Comparing base (6da1b79) to head (864991d).
⚠️ Report is 1 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #2969   +/-   ##
=======================================
  Coverage   96.15%   96.15%           
=======================================
  Files         309      309           
  Lines        7128     7128           
  Branches     1005     1005           
=======================================
  Hits         6854     6854           
  Misses        221      221           
  Partials       53       53           
Flag Coverage Δ
linux 96.15% <ø> (ø)
macos 96.15% <ø> (ø)
windows 96.14% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@martincostello martincostello merged commit 16d44f6 into main Mar 9, 2026
32 checks passed
@martincostello martincostello deleted the disable-secrets-outside-env branch March 9, 2026 11:43
IhateTrains pushed a commit to ParadoxGameConverters/ImperatorToCK3 that referenced this pull request Jun 11, 2026
Updated [Polly](https://github.com/App-vNext/Polly) from 8.6.6 to 8.7.0.

<details>
<summary>Release notes</summary>

_Sourced from [Polly's
releases](https://github.com/App-vNext/Polly/releases)._

## 8.7.0

## Highlights

* Adds caller cancellation token propagation in hedging and timeout
strategies by @​DaRosenberg in
App-vNext/Polly#3094
* Telemetry refactoring by @​martincostello in
App-vNext/Polly#2985

## What's Changed

* Update zizmor to 1.22.0 by @​martincostello in
App-vNext/Polly#2955
* Increase test timeout by @​martincostello in
App-vNext/Polly#2956
* Disable secrets-outside-env audit by @​martincostello in
App-vNext/Polly#2969
* Update zizmor to 1.23.1 by @​martincostello in
App-vNext/Polly#2970
* Update .NET NuGet packages by @​martincostello in
App-vNext/Polly#2982
* Add AGENTS.md by @​martincostello in
App-vNext/Polly#2983
* Fix typo in HTTP client integrations documentation by @​alexravenna in
App-vNext/Polly#2984
* Remove unused constant by @​martincostello in
App-vNext/Polly#2986
* Fix non-deterministic branch coverage in HedgingExecutionContext
hedging delay tests by @​Copilot in
App-vNext/Polly#2997
* Bump GitHubActionsTestLogger to 3.0.2 by @​martincostello in
App-vNext/Polly#3000
* Bump actionlint to v1.7.12 by @​martincostello in
App-vNext/Polly#3006
* Bump sign by @​martincostello in
App-vNext/Polly#3008
* Move Public API baselines by @​martincostello in
App-vNext/Polly#3016
* Formatting tweaks by @​martincostello in
App-vNext/Polly#3017
* Formatting tweaks by @​martincostello in
App-vNext/Polly#3018
* Remove ZIZMOR_VERSION by @​martincostello in
App-vNext/Polly#3025
* Assert nullable has result by @​martincostello in
App-vNext/Polly#3028
* Update deprecated action input by @​martincostello in
App-vNext/Polly#3035
* Move dependabot to Friday by @​martincostello in
App-vNext/Polly#3044
* Fix tag comment by @​martincostello in
App-vNext/Polly#3045
* Fix dependabot group by @​martincostello in
App-vNext/Polly#3047
* Pin runner images by @​martincostello in
App-vNext/Polly#3065
* Bump Refit to 10.2.0 by @​martincostello in
App-vNext/Polly#3096
* Disable Azure deployments by @​martincostello in
App-vNext/Polly#3105

## New Contributors

* @​alexravenna made their first contribution in
App-vNext/Polly#2984
* @​DaRosenberg made their first contribution in
App-vNext/Polly#3094

**Full Changelog**:
App-vNext/Polly@8.6.6...8.7.0


Commits viewable in [compare
view](App-vNext/Polly@8.6.6...8.7.0).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Polly&package-manager=nuget&previous-version=8.6.6&new-version=8.7.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
github-actions Bot pushed a commit to IntelliTect/EssentialCSharp.ListingManager that referenced this pull request Jun 11, 2026
Updated [Polly](https://github.com/App-vNext/Polly) from 8.6.6 to 8.7.0.

<details>
<summary>Release notes</summary>

_Sourced from [Polly's
releases](https://github.com/App-vNext/Polly/releases)._

## 8.7.0

## Highlights

* Adds caller cancellation token propagation in hedging and timeout
strategies by @​DaRosenberg in
App-vNext/Polly#3094
* Telemetry refactoring by @​martincostello in
App-vNext/Polly#2985

## What's Changed

* Update zizmor to 1.22.0 by @​martincostello in
App-vNext/Polly#2955
* Increase test timeout by @​martincostello in
App-vNext/Polly#2956
* Disable secrets-outside-env audit by @​martincostello in
App-vNext/Polly#2969
* Update zizmor to 1.23.1 by @​martincostello in
App-vNext/Polly#2970
* Update .NET NuGet packages by @​martincostello in
App-vNext/Polly#2982
* Add AGENTS.md by @​martincostello in
App-vNext/Polly#2983
* Fix typo in HTTP client integrations documentation by @​alexravenna in
App-vNext/Polly#2984
* Remove unused constant by @​martincostello in
App-vNext/Polly#2986
* Fix non-deterministic branch coverage in HedgingExecutionContext
hedging delay tests by @​Copilot in
App-vNext/Polly#2997
* Bump GitHubActionsTestLogger to 3.0.2 by @​martincostello in
App-vNext/Polly#3000
* Bump actionlint to v1.7.12 by @​martincostello in
App-vNext/Polly#3006
* Bump sign by @​martincostello in
App-vNext/Polly#3008
* Move Public API baselines by @​martincostello in
App-vNext/Polly#3016
* Formatting tweaks by @​martincostello in
App-vNext/Polly#3017
* Formatting tweaks by @​martincostello in
App-vNext/Polly#3018
* Remove ZIZMOR_VERSION by @​martincostello in
App-vNext/Polly#3025
* Assert nullable has result by @​martincostello in
App-vNext/Polly#3028
* Update deprecated action input by @​martincostello in
App-vNext/Polly#3035
* Move dependabot to Friday by @​martincostello in
App-vNext/Polly#3044
* Fix tag comment by @​martincostello in
App-vNext/Polly#3045
* Fix dependabot group by @​martincostello in
App-vNext/Polly#3047
* Pin runner images by @​martincostello in
App-vNext/Polly#3065
* Bump Refit to 10.2.0 by @​martincostello in
App-vNext/Polly#3096
* Disable Azure deployments by @​martincostello in
App-vNext/Polly#3105

## New Contributors

* @​alexravenna made their first contribution in
App-vNext/Polly#2984
* @​DaRosenberg made their first contribution in
App-vNext/Polly#3094

**Full Changelog**:
App-vNext/Polly@8.6.6...8.7.0


Commits viewable in [compare
view](App-vNext/Polly@8.6.6...8.7.0).
</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Jun 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants