Skip to content

ci: replace fragile secret-scan ignore with a placeholder allowlist - #31

Merged
darthrootbeer merged 1 commit into
mainfrom
ci/gitleaks-allowlist
Oct 2, 2026
Merged

darthrootbeer merged 1 commit into
mainfrom
ci/gitleaks-allowlist

Conversation

@darthrootbeer

Copy link
Copy Markdown
Owner

Context

The latest commit on main shows a red CI X: the secret scan flags the fake token in the docs-pipeline sample curl command, because the ignore entry named a pre-squash commit hash. Cold review 2, finding H1. Ticket: JBSR-099.

Changes

  • Delete .gitleaksignore.
  • Add .gitleaks.toml: extends the default rules and allows only the placeholder text YOUR_API_KEY, so squash merges no longer break it.

🤖 Generated with Claude Code

https://claude.ai/code/session_01XV3Ggh86cf2xwUyz28XaN6

  • Docs updated

The old ignore entry named a pre-squash commit hash, so every squash merge
re-triggered the finding. A .gitleaks.toml that extends the default rules and
allows only the YOUR_API_KEY placeholder does not depend on commit hashes.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XV3Ggh86cf2xwUyz28XaN6
@darthrootbeer
darthrootbeer merged commit af952f5 into main Oct 2, 2026
6 checks passed
@darthrootbeer
darthrootbeer deleted the ci/gitleaks-allowlist branch October 2, 2026 03:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant