From 1d73efed1e9ccf88f48523eb02e9130f3a3bf9cb Mon Sep 17 00:00:00 2001 From: darthrootbeer Date: Thu, 1 Oct 2026 23:03:07 -0400 Subject: [PATCH] ci: replace fragile secret-scan ignore with a placeholder allowlist The old ignore entry named a pre-squash commit hash, so every squash merge re-triggered the finding. A .gitleaks.toml that extends the default rules and allows only the YOUR_API_KEY placeholder does not depend on commit hashes. Co-Authored-By: Claude Sonnet 5.5 Claude-Session: https://claude.ai/code/session_01XV3Ggh86cf2xwUyz28XaN6 --- .gitleaks.toml | 12 ++++++++++++ .gitleaksignore | 3 --- 2 files changed, 12 insertions(+), 3 deletions(-) create mode 100644 .gitleaks.toml delete mode 100644 .gitleaksignore diff --git a/.gitleaks.toml b/.gitleaks.toml new file mode 100644 index 0000000..9002d0d --- /dev/null +++ b/.gitleaks.toml @@ -0,0 +1,12 @@ +# Extends the default gitleaks rules and allows one thing only: the fake +# placeholder YOUR_API_KEY used in a sample curl command. It is not a credential. +# Matching on the placeholder text (not a commit hash) keeps it working +# after squash merges, which create new commit hashes. +title = "context-engineering-toolkit" + +[extend] +useDefault = true + +[allowlist] +description = "Placeholder API key in documentation examples" +regexes = ['''YOUR_API_KEY'''] diff --git a/.gitleaksignore b/.gitleaksignore deleted file mode 100644 index a31d15e..0000000 --- a/.gitleaksignore +++ /dev/null @@ -1,3 +0,0 @@ -# Placeholder token in a sample curl command (Authorization: Bearer YOUR_API_KEY), docs-pipeline sample doc. -# It is a fake value in a made-up example, not a credential. The line sits in an earlier commit of PR 30, which cannot be rewritten. -445b46ad65f98f2e34928eaf9340d5417edcde79:pipelines/docs-pipeline/sample/acme-orders-cancellations.md:curl-auth-header:22