1.3 KiB
1.3 KiB
WRNexusJS 0.7.0 R1 — Local environment audit boundary
Problem
The security audit recursively scanned every file in the working directory. Local, ignored environment files such as examples/basic-app/.env and .env.uat therefore failed the release audit even though they were not tracked by Git and would not be published.
Fix
- Release security checks now scan
git ls-files -zwhen Git metadata is available. - Secret-like files tracked by Git still fail with
SEC-NO-TRACKED-SECRET-FILES. - Ignored or untracked local secret files produce
SEC-LOCAL-SECRET-FILESwarnings only. - Source archives without
.gitmetadata still scan every included file. - The JSON report schema is updated to version 2 and includes warnings separately from errors.
Existing repositories
If old .env files are still tracked, remove them from the Git index while retaining local copies:
git rm --cached examples/basic-app/.env examples/basic-app/.env.uat
git add examples/basic-app/.env.example examples/basic-app/.env.uat.example .gitignore
git commit -m "security(examples): stop tracking local environment files"
The root .gitignore now also explicitly allows environment templates for named environments:
!.env.example
!.env.*.example