Skip to content

chore(secrets): add manifest receipt secret - #3468

Merged
WcaleNieWolny merged 1 commit into
mainfrom
wolny/update-manifest-receipt-secret
Sep 27, 2026
Merged

WcaleNieWolny merged 1 commit into
mainfrom
wolny/update-manifest-receipt-secret

Conversation

@WcaleNieWolny

@WcaleNieWolny WcaleNieWolny commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Summary

  • add MANIFEST_SIZE_RECEIPT_SECRET to the encrypted production environment
  • update the git-secret integrity mapping
  • keep the plaintext production environment ignored and out of git

Validation

  • confirmed the encrypted artifact decrypts to the recorded SHA-256 checksum
  • compared environment variable names against main; only MANIFEST_SIZE_RECEIPT_SECRET was added
  • confirmed internal/cloudflare/.env.prod remains ignored and untracked
  • git diff --check

Follow-up to #3465.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Review in cubic

@coderabbitai

coderabbitai Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 51 seconds.

Check out review usage here.

View limit details

Limit details: You’ve used all 2 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 99d3998d-f829-408d-9041-4fc424d4a18f

📥 Commits

Reviewing files that changed from the base of the PR and between 384ec2e and 0ed5303.

📒 Files selected for processing (2)
  • .gitsecret/paths/mapping.cfg
  • internal/cloudflare/.env.prod.secret

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codspeed

codspeed Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

✅ 43 untouched benchmarks
⏩ 2 skipped benchmarks1


Comparing wolny/update-manifest-receipt-secret (0ed5303) with main (384ec2e)

Open in CodSpeed

Footnotes

  1. 2 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

@sonarqubecloud

Copy link
Copy Markdown

@WcaleNieWolny
WcaleNieWolny merged commit 481ce0a into main Sep 27, 2026
93 of 97 checks passed
@WcaleNieWolny
WcaleNieWolny deleted the wolny/update-manifest-receipt-secret branch September 27, 2026 10:33

This branch was successfully deployed

1 active deployment
deepsec-pr — 0ed5303a Deployed Sep 26, 2026 by WcaleNieWolny via Scan PR changes #7851
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant