Skip to content

feat(sdk): added secrets as first class concepts and examples#739

Merged
james-rl merged 5 commits into
mainfrom
james/secrets
Mar 6, 2026
Merged

feat(sdk): added secrets as first class concepts and examples#739
james-rl merged 5 commits into
mainfrom
james/secrets

Conversation

@james-rl

@james-rl james-rl commented Mar 3, 2026

Copy link
Copy Markdown
Contributor

User description

⚠️ PR Title Must Follow Conventional Commits

Format: feat[optional scope]: <description>

Examples: feat: add new SDK method · feat(storage): support file uploads · feat!: breaking API change

Description

Added secrets to SDK, along with examples and tests.

Motivation

Changes

Testing

  • Unit tests added
  • Integration tests added
  • Smoke Tests added/updated
  • Tested locally

Breaking Changes

Checklist

  • PR title follows Conventional Commits format (feat: or feat(scope):)
  • Documentation updated (if needed)
  • Breaking changes documented (if applicable)

CodeAnt-AI Description

Add first-class Secret support and devbox integration (create, inject, verify, delete)

What Changed

  • SDK exposes Secret as an object and a new secret operations surface (create, update, list, delete, fromName) so callers can manage secrets via object-oriented APIs
  • Devbox creation now accepts secrets (Secret objects or names) and MCP/gateway specs can receive Secret objects so secrets are injected into devboxes as environment variables
  • Examples, smoketests, and docs added/updated: new example shows creating a secret, injecting it into a devbox, verifying access, updating and deleting; smoketests cover secret lifecycle and devbox integration

Impact

✅ Shorter secret setup for devboxes
✅ Fewer manual API calls to inject secrets
✅ Clearer secret lifecycle verification in examples and tests

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

@codeant-ai

codeant-ai Bot commented Mar 3, 2026

Copy link
Copy Markdown
Contributor

CodeAnt AI is reviewing your PR.


Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@codeant-ai codeant-ai Bot added the size:XL This PR changes 500-999 lines, ignoring generated files label Mar 3, 2026
@codeant-ai

codeant-ai Bot commented Mar 3, 2026

Copy link
Copy Markdown
Contributor

Nitpicks 🔍

🔒 No security issues identified
⚡ Recommended areas for review

  • Hardcoded Secret
    The example commits concrete secret values into source (both initial and updated values). Hardcoded secrets in examples can be accidentally committed to VCS or leaked in logs; they should be provided from environment or generated dynamically for tests.

  • Plaintext secrets in devbox test
    The devbox-integration test injects a plaintext secret ('secret-for-devbox-test') and asserts it appears in the devbox environment. Ensure CI logging and test artifacts cannot leak this value, and confirm tests run in isolated environments.

  • Plaintext secrets in tests
    Tests create secrets using hard-coded plaintext values (e.g. 'test-secret-value'). These values can be recorded in CI logs or artifacts. Consider generating secrets dynamically from env or ensuring logs are redacted.

  • Inefficient lookup
    getInfo() lists up to 5000 secrets then does an in-memory find by name. This is inefficient and fragile for large accounts (could miss secrets if >5000) and will be slower than a direct lookup or server-side filter. Consider using a dedicated get-by-name endpoint or server filtering/pagination.

  • Secret resolution
    The helper resolveSecretName assumes a Secret object always has a name property and returns it directly. If the Secret shape changes or an object missing name is passed, callers will receive undefined (or a runtime error if later used). Validate/fallback or throw early to avoid sending invalid names to the API.

@codeant-ai

codeant-ai Bot commented Mar 3, 2026

Copy link
Copy Markdown
Contributor

CodeAnt AI finished reviewing your PR.

@github-actions

github-actions Bot commented Mar 3, 2026

Copy link
Copy Markdown

⚠️ Object Smoke Tests & Coverage Report

Test Results

✅ All smoke tests passed

Coverage Results

Metric Coverage Required Status
Functions 96.98% 100%
Lines 87.85% - ℹ️
Branches 66.52% - ℹ️
Statements 86.67% - ℹ️

Coverage Requirement: 100% function coverage (all public methods must be called in smoke tests)

⚠️ Some object methods are not covered in smoke tests. Please add tests that call all public methods.

View detailed coverage report
File Functions Lines Branches
src/sdk.ts ❌ 98.57% 84.65% 72.58%
src/sdk/agent.ts ✅ 100% 100% 100%
src/sdk/blueprint.ts ✅ 100% 100% 80%
src/sdk/devbox.ts ❌ 97.56% 90.99% 96.96%
src/sdk/execution-result.ts ✅ 100% 92.68% 70.83%
src/sdk/execution.ts ✅ 100% 94.11% 83.33%
src/sdk/gateway-config.ts ✅ 100% 100% 100%
src/sdk/mcp-config.ts ✅ 100% 100% 100%
src/sdk/network-policy.ts ❌ 42.85% 50% 100%
src/sdk/scenario-run.ts ✅ 100% 96.87% 50%
src/sdk/scenario.ts ✅ 100% 100% 100%
src/sdk/scorer.ts ✅ 100% 100% 100%
src/sdk/secret.ts ❌ 87.5% 91.66% 100%
src/sdk/snapshot.ts ✅ 100% 100% 100%
src/sdk/storage-object.ts ✅ 100% 80% 48.93%

📋 View workflow run

@james-rl
james-rl requested review from dines-rl and tode-rl March 3, 2026 21:59
@codeant-ai

codeant-ai Bot commented Mar 6, 2026

Copy link
Copy Markdown
Contributor

CodeAnt AI is running Incremental review


Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@codeant-ai codeant-ai Bot added size:XL This PR changes 500-999 lines, ignoring generated files and removed size:XL This PR changes 500-999 lines, ignoring generated files labels Mar 6, 2026
@codeant-ai

codeant-ai Bot commented Mar 6, 2026

Copy link
Copy Markdown
Contributor

CodeAnt AI Incremental review completed.

@james-rl

james-rl commented Mar 6, 2026

Copy link
Copy Markdown
Contributor Author

Added GET /secret/{name}/ to the backend and now this uses it too

const secretName = uniqueName('example-github-mcp');
await sdk.api.secrets.create({
const secretName = 'GITHUB_MCP_EXAMPLE';
const secret = await sdk.secret.create({

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

use your new endpoint 🥳

@james-rl
james-rl merged commit c82944a into main Mar 6, 2026
9 checks passed
@james-rl
james-rl deleted the james/secrets branch March 6, 2026 01:47
@stainless-app stainless-app Bot mentioned this pull request Mar 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL This PR changes 500-999 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants