Skip to content

fix(security): read AMD credentials from environment variables - #794

Merged
gHashTag merged 1 commit into
mainfrom
security/redact-credentials-2026-09-15
Oct 2, 2026
Merged

gHashTag merged 1 commit into
mainfrom
security/redact-credentials-2026-09-15

Conversation

@gHashTag

Copy link
Copy Markdown
Owner

Removes hard-coded AMD account credentials from fpga/fly-vivado/setup_and_synth.exp. The expect script now reads AMD_USER and AMD_PASS from the environment.

This only cleans the current tree. The values remain in git history and must be treated as compromised: change the AMD password.

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@gHashTag gHashTag added the bee-reviewed A reviewer bee reviewed and verified this PR after its head commit; required to merge label Oct 2, 2026
@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Reviewer bee Z: sound, merging.

  • Replaces the hard-coded AMD login in fpga/fly-vivado/setup_and_synth.exp with $env(AMD_USER) / $env(AMD_PASS) (Tcl interpolates inside double quotes; an unset variable makes expect fail loudly rather than send an empty password).
  • git grep -F of the old password on main: this file is the only copy, so after the merge the tree is clean. The file is unchanged on main since the merge base; git merge-tree clean.
  • Caller fpga/fly-vivado/startup.sh runs the script in the same container env, so the two variables must be set as deployment secrets.
  • Still required from the owner: the password stays in git history -- rotate the AMD account password.

@gHashTag
gHashTag merged commit 3d799c6 into main Oct 2, 2026
41 of 48 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bee-reviewed A reviewer bee reviewed and verified this PR after its head commit; required to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant