Skip to content

chore: ignore the key-shaped GCS fixture gitleaks finds in history - #526

Merged
BryanFRD merged 1 commit into
mainfrom
chore/gitleaks-ignore-fixture
Oct 3, 2026
Merged

BryanFRD merged 1 commit into
mainfrom
chore/gitleaks-ignore-fixture

Conversation

@BryanFRD

@BryanFRD BryanFRD commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Refs #520

#525 replaced the PEM-shaped test string that gitleaks reports as a private key, but the security scan runs gitleaks detect over the whole history, so the commit from #521 that still carries it raises code scanning alert 346 on every run. It was never a key: the test only needed text that is not an RSA key.

.gitleaksignore names that one finding by its fingerprint (commit, file, rule, line), so any other key-shaped string anywhere is still reported. Checked locally with gitleaks 8.21.2, the version the shared workflow installs: the finding is gone with the file and back without it.

@BryanFRD
BryanFRD enabled auto-merge (squash) October 3, 2026 10:41

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I checked the flagged line at 26da6aa. It is the "-----BEGIN PRIVATE KEY-----\nnot a key\n..." placeholder in a_credentials_file_that_cannot_serve_refuses_to_start, so it is not a real secret. The ignore entry is a full fingerprint (commit, file, rule, line), which means it can't hide a different finding. No blocking issues.

@BryanFRD
BryanFRD merged commit e5696ed into main Oct 3, 2026
27 checks passed
@BryanFRD
BryanFRD deleted the chore/gitleaks-ignore-fixture branch October 3, 2026 10:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant