Skip to content

Add secret-zero bootstrap gates#2210

Open
Dolpme wants to merge 1 commit into
UnitOneAI:mainfrom
Dolpme:improve/secrets-secret-zero-bootstrap
Open

Add secret-zero bootstrap gates#2210
Dolpme wants to merge 1 commit into
UnitOneAI:mainfrom
Dolpme:improve/secrets-secret-zero-bootstrap

Conversation

@Dolpme

@Dolpme Dolpme commented Jun 9, 2026

Copy link
Copy Markdown

Addresses #2064.

Summary

  • Adds secret-zero/bootstrap evidence gates to the secrets-management skill.
  • Requires paired bootstrap factor separation, OIDC/workload identity claim binding, AppRole fallback controls, exchanged-token non-persistence checks, and audit correlation.
  • Updates severity guidance, report output, common pitfalls, and the skill changelog.

Validation

  • git diff --check
  • Frontmatter required-field check across skills/ and roles/
  • index.yaml referenced-file existence check
  • Markdown fence-balance check for skills/devsecops/secrets-management/SKILL.md
  • Target marker check for secret-zero, paired AppRole factors, OIDC/workload identity, non-persistence evidence, audit correlation, and version 1.0.2
  • Changed-file prompt-injection pattern check

Bounty note: this is intended as an improver-tier contribution under CONTRIBUTING.md; payment details can be provided privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant