UNCLASSIFIED - NO CUI

Trufflehog failure

Summary

Development is failing the trufflehog job in the hardening pipeline. Requesting approval from CHT security to perform the cleanup of the repo. The helm/ dir that is causing the failure, is no longer present in the repo, indicating it should be removed from history, as opposed to being whitelisted.

Link to failed pipeline

https://repo1.dso.mil/dsop/jfrog/artifactory/artifactory-oss/-/jobs/4172804

What is the current bug behavior?

trufflehog fails

What is the expected correct behavior?

trufflehog passes

Possible fixes

clean up the commit history to remove refs to the helm/ directory

Definition of Done

  • Pipeline failure has been resolved

/cc @ironbank-notifications/pipelines /cc @ironbank-notifications/security

Edited by Daniel Miakotkin