chore(security): gitleaks allowlist for triaged false positives - #467
Conversation
The gitleaks gate has been blocking this repository's pull requests. Every finding was triaged on 2026-08-06 by reading the matched line with the value redacted, and every one is a false positive. No live credential was found. Each entry names WHAT THE VALUE ACTUALLY IS rather than saying the file is noisy — an algorithm name, a bibliographic key, a published protocol constant, a fixture belonging to a secret DETECTOR, and so on. The file EXTENDS the estate baseline rather than replacing it: hyperpolymath/standards secret-scanner-reusable.yml stages that baseline at the workspace root as .gitleaks-estate.toml, and gitleaks resolves '[extend] path' against the process CWD. Requires standards#584. Kept local rather than promoted to the estate baseline because every entry is a blind spot: held here it blinds this repository only, with its justification beside the code it describes. Verified before commit: with this config in place a planted AWS canary outside the exempted paths is still DETECTED and the gate still exits non-zero on it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
| paths = [ | ||
| # Unit tests for cipherbot's hardcoded-secret DETECTOR. The fixtures must | ||
| # look like secrets or the tests cannot assert that the detector rejects | ||
| # them. | ||
| '''(^|/)bots/cipherbot/src/analyzers/config\.rs$''', | ||
|
|
||
| ] |
There was a problem hiding this comment.
💡 Edge Case: Allowlist may miss secret-like test fixture weak_config.toml
The allowlist exempts only bots/cipherbot/src/analyzers/config.rs, but a sibling test fixture bots/cipherbot/tests/fixtures/weak_config.toml also contains a credential-shaped literal (password = "SuperSecretPassword123!") that exists purely to exercise the detector. If the estate baseline's rules flag this value, the gate will fail on this repo even though it is a false positive of the same class the PR is triaging. Confirm whether gitleaks flags this fixture and, if so, add an anchored path entry for it (e.g. '''(^|/)bots/cipherbot/tests/fixtures/weak_config.toml$''').
Was this helpful? React with 👍 / 👎
There was a problem hiding this comment.
Configure merge blocking · Maintainers can dismiss this review.
|
Note Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime. Code Review 👍 Approved with suggestions 0 resolved / 1 findingsAdds a Gitleaks allowlist for triaged false positives to clear scanner gates. The allowlist may miss the secret-like test fixture weak_config.toml since it only exempts bots/cipherbot/src/analyzers/config.
💡 Edge Case: Allowlist may miss secret-like test fixture weak_config.tomlThe allowlist exempts only bots/cipherbot/src/analyzers/config.rs, but a sibling test fixture bots/cipherbot/tests/fixtures/weak_config.toml also contains a credential-shaped literal (password = "SuperSecretPassword123!") that exists purely to exercise the detector. If the estate baseline's rules flag this value, the gate will fail on this repo even though it is a false positive of the same class the PR is triaging. Confirm whether gitleaks flags this fixture and, if so, add an anchored path entry for it (e.g. '''(^|/)bots/cipherbot/tests/fixtures/weak_config.toml$'''). 🤖 Prompt for agentsOptionsDisplay: compact → Showing less information. Comment with these commands to change the behavior for this request:
Important Your trial ends in 4 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more. Was this helpful? React with 👍 / 👎 | Gitar |
All of this repository's gitleaks findings were triaged on 2026-08-06 by reading each matched line with the value redacted. Every one is a false positive — no live credential was found.
This adds locally justified path exemptions. Each names what the value actually is rather than saying a file is noisy.
Why local and not in the estate baseline: every entry is a blind spot. Held here it blinds this repository only, and the justification sits beside the code it describes. Promoted to the baseline it would blind all 400+ repositories.
Depends on hyperpolymath/standards#584, which wires the estate baseline into the scan and stages it at the workspace root so this file's
[extend] pathresolves.Verified before commit: with this config in place, a planted AWS canary outside the exempted paths is still DETECTED and the gate still exits non-zero.
🤖 Generated with Claude Code