Context: .pre-commit-config.yaml runs detect-secrets with --baseline .secrets.baseline; the file ls confirms is absent from the repo root.
Problem: pre-commit will fail (or run un-baselined) on every invocation: either the baseline is missing so the hook errors, or secrets already committed never get baselined - the hook's value is nil and developers hit a failing gate.
Proposed approach: Create .secrets.baseline (empty or with audited findings) and commit it, or drop the --baseline arg + hook until secrets scanning is intentional; document the expected baseline workflow.
Acceptance criteria: pre-commit run detect-secrets passes; baseline file exists and matches repo scan.
Context:
.pre-commit-config.yamlrunsdetect-secretswith--baseline .secrets.baseline; the filelsconfirms is absent from the repo root.Problem: pre-commit will fail (or run un-baselined) on every invocation: either the baseline is missing so the hook errors, or secrets already committed never get baselined - the hook's value is nil and developers hit a failing gate.
Proposed approach: Create
.secrets.baseline(empty or with audited findings) and commit it, or drop the--baselinearg + hook until secrets scanning is intentional; document the expected baseline workflow.Acceptance criteria:
pre-commit run detect-secretspasses; baseline file exists and matches repo scan.