chore(security): gitleaks allowlist for triaged false positives - #345
chore(security): gitleaks allowlist for triaged false positives#345hyperpolymath wants to merge 1 commit into
Conversation
The gitleaks gate has been blocking this repository's pull requests. Every finding was triaged on 2026-08-06 by reading the matched line with the value redacted, and every one is a false positive. No live credential was found. Each entry names WHAT THE VALUE ACTUALLY IS rather than saying the file is noisy — an algorithm name, a bibliographic key, a published protocol constant, a fixture belonging to a secret DETECTOR, and so on. The file EXTENDS the estate baseline rather than replacing it: hyperpolymath/standards secret-scanner-reusable.yml stages that baseline at the workspace root as .gitleaks-estate.toml, and gitleaks resolves '[extend] path' against the process CWD. Requires standards#584. Kept local rather than promoted to the estate baseline because every entry is a blind spot: held here it blinds this repository only, with its justification beside the code it describes. Verified before commit: with this config in place a planted AWS canary outside the exempted paths is still DETECTED and the gate still exits non-zero on it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
|
Note Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime. Code Review ✅ ApprovedAdds a local gitleaks allowlist with path exemptions for triaged false positives while keeping security gates active for unexempted paths. No issues found.
OptionsDisplay: compact → Showing less information. Comment with these commands to change the behavior for this request:
Important Your trial ends in 4 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more. Was this helpful? React with 👍 / 👎 | Gitar |
All of this repository's gitleaks findings were triaged on 2026-08-06 by reading each matched line with the value redacted. Every one is a false positive — no live credential was found.
This adds locally justified path exemptions. Each names what the value actually is rather than saying a file is noisy.
Why local and not in the estate baseline: every entry is a blind spot. Held here it blinds this repository only, and the justification sits beside the code it describes. Promoted to the baseline it would blind all 400+ repositories.
Depends on hyperpolymath/standards#584, which wires the estate baseline into the scan and stages it at the workspace root so this file's
[extend] pathresolves.Verified before commit: with this config in place, a planted AWS canary outside the exempted paths is still DETECTED and the gate still exits non-zero.
🤖 Generated with Claude Code