FedML icon indicating copy to clipboard operation
FedML copied to clipboard

[Test] refactor Github Actions Used for FedML-AI/FedML CI

Open xiang-wang-innovator opened this issue 1 year ago • 1 comments

WIP

xiang-wang-innovator avatar Jun 18 '24 08:06 xiang-wang-innovator

⚠️ GitGuardian has uncovered 24 secrets following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secrets in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
- Generic High Entropy Secret 008266ff6ef9c36469293695848952dbe32311fe devops/dockerfile/github-action-runner/DockerfileWx View secret
- Generic High Entropy Secret e25ad75809b7ce0ffc1e5bd88af4446d8036149c devops/dockerfile/github-action-runner/DockerfileLight View secret
- Generic High Entropy Secret c4ec02dc3f066cc5b143f1798dee6e1e16ed07b5 devops/dockerfile/github-action-runner/Dockerfile View secret
- Generic High Entropy Secret ea9320b9761eda241e40ca96ddcd503085efed00 devops/dockerfile/github-action-runner/Dockerfile View secret
- Generic High Entropy Secret c4ec02dc3f066cc5b143f1798dee6e1e16ed07b5 devops/dockerfile/github-action-runner/DockerfileLight View secret
- Generic High Entropy Secret 742862f7b07e4577345662f268b10ce3a3a2592d devops/dockerfile/github-action-runner/DockerfileLight View secret
- Generic High Entropy Secret f3fa51b0299201f46a440ef7f4cfa15dc2090671 devops/dockerfile/github-action-runner/Dockerfile View secret
- Generic High Entropy Secret 11ab6580d4fde98b85a6abea433198cd5c7777b7 devops/dockerfile/github-action-runner/Dockerfile View secret
- Generic High Entropy Secret 742862f7b07e4577345662f268b10ce3a3a2592d devops/dockerfile/github-action-runner/Dockerfile View secret
5692101 Triggered Generic High Entropy Secret 12750349545bbda4ca9984723221a5f504b614d6 python/fedml/computing/scheduler/model_scheduler/device_model_deployment.py View secret
5692101 Triggered Generic High Entropy Secret 3fbaaee8c5a38888834817e8fff782ce703bc3b1 python/fedml/computing/scheduler/model_scheduler/device_model_deployment.py View secret
5692101 Triggered Generic High Entropy Secret f3fa51b0299201f46a440ef7f4cfa15dc2090671 python/fedml/computing/scheduler/model_scheduler/device_model_deployment.py View secret
- Generic CLI Secret 11ab6580d4fde98b85a6abea433198cd5c7777b7 devops/dockerfile/github-action-runner/WindowsDockerfile View secret
- Generic CLI Secret ea9320b9761eda241e40ca96ddcd503085efed00 devops/dockerfile/github-action-runner/WindowsDockerfile View secret
- Generic CLI Secret f3fa51b0299201f46a440ef7f4cfa15dc2090671 devops/dockerfile/github-action-runner/WindowsDockerfile View secret
9453265 Triggered Generic High Entropy Secret ea9320b9761eda241e40ca96ddcd503085efed00 python/tests/test_train/test_train.py View secret
9453265 Triggered Generic High Entropy Secret ea9320b9761eda241e40ca96ddcd503085efed00 python/fedml/api/api_test.py View secret
9453265 Triggered Generic High Entropy Secret f3fa51b0299201f46a440ef7f4cfa15dc2090671 python/fedml/api/api_test.py View secret
- Generic High Entropy Secret e25ad75809b7ce0ffc1e5bd88af4446d8036149c devops/dockerfile/github-action-runner/DockerfileLight View secret
- Generic High Entropy Secret 295ca57525444966b7a9f50682fb7a949c6f3cce devops/dockerfile/github-action-runner/DockerfileLight View secret
- Generic High Entropy Secret c4ec02dc3f066cc5b143f1798dee6e1e16ed07b5 devops/dockerfile/github-action-runner/DockerfileLight View secret
- Generic High Entropy Secret 295ca57525444966b7a9f50682fb7a949c6f3cce devops/dockerfile/github-action-runner/DockerfileLight View secret
5692101 Triggered Generic High Entropy Secret 853097349e1fb48ae375904e95c10e288650947d python/fedml/computing/scheduler/model_scheduler/device_model_deployment.py View secret
5692101 Triggered Generic High Entropy Secret 23d88fc7dcfdbe9f9b319a08b72b39f0c58fdbb3 python/fedml/computing/scheduler/model_scheduler/device_model_deployment.py View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

gitguardian[bot] avatar Jun 18 '24 08:06 gitguardian[bot]