You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I want to ensure that Fleet binaries don't embed secrets or secret-looking artifacts
so that I can have better assurance of a cleaner software supply chain.
Original requests
Context: We're pulling crewjam/saml into fleetctl's binary because of transitive dependencies from fleetctl code. This caused a flag that's being fixed by crewjam/saml#646. A customer caught this via GitHub Enterprise secret scanning.
Goal
Original requests
Context: We're pulling crewjam/saml into
fleetctl's binary because of transitive dependencies from fleetctl code. This caused a flag that's being fixed by crewjam/saml#646. A customer caught this via GitHub Enterprise secret scanning.More context in Slack
Resources
Changes
Engineering
QA
Risk assessment
Test plan
Testing notes
Confirmation