Repository navigation
Secrets never block a task: take them out of the branch and push it - #54
Merged
Merged
Conversation
Coding tasks landed in Blocked far too often with "The changes on <branch> contain a secret saved in the vault, so Godmode didn't push them". The check compared the whole `git diff base...HEAD` (context lines, removed lines and file paths included) with every value the vault masks, and that is every value of every custom MCP server's env and headers — `production`, URLs, regions. Any branch touching a config file could trip it. What counts now - Only what the commits a push would publish add (neither on the base nor on the remote yet): added lines, file names, commit messages, files that look like secrets (.env, keys) and every version of a binary file (read whole, up to 20 MB). Removed and surrounding lines don't count, a moved file adds only what changed. - Only values stored as a secret (`pushSecrets`, a subset of the redaction list): passwords, 2FA secrets, API keys, tokens; of MCP env/header and messaging maps the values whose name says secret (API_KEY, signingKey, SENTRY_DSN, SLACK_WEBHOOK_URL, Authorization — not publishable/anon keys, not SORT_KEY=created_at), bearer tokens and URL passwords; never a single plain word or number. Redaction in transcripts and logs is unchanged. What happens instead of Blocked (`removeSecrets`, tasks/git.ts) - The secret is replaced with GODMODE_REMOVED_SECRET in text files; files that look like secrets, binaries holding one and files that can't be rewritten safely (not UTF-8, a link, not writable) are left out — they stay in the worktree, and one the branch already had keeps the remote's version. - The unpushed commits become one commit on top of what the remote has (the branch's own last commit first), so no pushed commit or message carries the secret and nothing on the remote is rewritten. The branch as the agent left it stays in the worktree as refs/worktree/godmode/with-secrets/<sha>. - Exactly the commit that was checked is pushed. A turn that stages or commits during the fix (or before a merge with someone else's push) makes Godmode skip this push; that turn's end pushes the branch. - A warning names what was changed; the agent's brief asks it to read secrets from the environment; PR title and body never carry a saved secret, even with redaction off. SecretInBranch and its three catch sites (publish, keepWork, pushTaskBranch) are gone. Tasks already blocked with the old message push normally from the board or when moved to Todo.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Coding tasks landed in Blocked far too often with "The changes on contain a secret saved in the vault, so Godmode didn't push them". Now a secret never stops a push and never goes along: Godmode takes it out of the branch, pushes, and notifies.
Why it fired so often
git diff base...HEAD, so context lines, removed lines and file paths all counted.production, URLs, regions), so any branch touching a config file could trip it.What counts now
.env/key files; and every version of a binary file (≤ 20 MB). Moved files count only for what changed.pushSecretssubset; transcript redaction is unchanged):API_KEY,signingKey,SENTRY_DSN,SLACK_WEBHOOK_URL,Authorization) — not publishable/anon keys, notSORT_KEY=created_at;Instead of Blocked (
removeSecretsintasks/git.ts)GODMODE_REMOVED_SECRET.refs/worktree/godmode/with-secrets/<sha>and is never pushed.SecretInBranchand its three catch sites (publish,keepWork,pushTaskBranch) are removed. Tasks already blocked with the old message push normally from the board, or when moved to Todo.Trade-offs
postgres) is no longer kept out of pushes. It is still masked.Tests
bun testinpackages/corepasses 1056; the one failure (folder routes > list subfolders…) fails onmaintoo.tsc --noEmitis clean.tasks.test.ts/vault.test.ts:.envfile;