Repository navigation
chore: ignore the key-shaped GCS fixture gitleaks finds in history - #526
Merged
Merged
Conversation
BryanFRD
enabled auto-merge (squash)
October 3, 2026 10:41
Contributor
There was a problem hiding this comment.
I checked the flagged line at 26da6aa. It is the "-----BEGIN PRIVATE KEY-----\nnot a key\n..." placeholder in a_credentials_file_that_cannot_serve_refuses_to_start, so it is not a real secret. The ignore entry is a full fingerprint (commit, file, rule, line), which means it can't hide a different finding. No blocking issues.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #520
#525 replaced the PEM-shaped test string that gitleaks reports as a private key, but the security scan runs
gitleaks detectover the whole history, so the commit from #521 that still carries it raises code scanning alert 346 on every run. It was never a key: the test only needed text that is not an RSA key..gitleaksignorenames that one finding by its fingerprint (commit, file, rule, line), so any other key-shaped string anywhere is still reported. Checked locally with gitleaks 8.21.2, the version the shared workflow installs: the finding is gone with the file and back without it.