Skip to content

chore(security): gitleaks allowlist for triaged false positives - #106

Merged
hyperpolymath merged 2 commits into
mainfrom
chore/gitleaks-allowlist
Aug 7, 2026
Merged

chore(security): gitleaks allowlist for triaged false positives#106
hyperpolymath merged 2 commits into
mainfrom
chore/gitleaks-allowlist

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

All of this repository's gitleaks findings were triaged on 2026-08-06 by reading each matched line with the value redacted. Every one is a false positive — no live credential was found.

This adds locally justified path exemptions. Each names what the value actually is rather than saying a file is noisy.

Why local and not in the estate baseline: every entry is a blind spot. Held here it blinds this repository only, and the justification sits beside the code it describes. Promoted to the baseline it would blind all 400+ repositories.

Depends on hyperpolymath/standards#584, which wires the estate baseline into the scan and stages it at the workspace root so this file's [extend] path resolves.

Verified before commit: with this config in place, a planted AWS canary outside the exempted paths is still DETECTED and the gate still exits non-zero.

🤖 Generated with Claude Code

The gitleaks gate has been blocking this repository's pull requests. Every
finding was triaged on 2026-08-06 by reading the matched line with the value
redacted, and every one is a false positive. No live credential was found.

Each entry names WHAT THE VALUE ACTUALLY IS rather than saying the file is
noisy — an algorithm name, a bibliographic key, a published protocol
constant, a fixture belonging to a secret DETECTOR, and so on.

The file EXTENDS the estate baseline rather than replacing it:
hyperpolymath/standards secret-scanner-reusable.yml stages that baseline at
the workspace root as .gitleaks-estate.toml, and gitleaks resolves
'[extend] path' against the process CWD. Requires standards#584.

Kept local rather than promoted to the estate baseline because every entry is
a blind spot: held here it blinds this repository only, with its
justification beside the code it describes.

Verified before commit: with this config in place a planted AWS canary
outside the exempted paths is still DETECTED and the gate still exits
non-zero on it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@gitar-bot

This comment has been minimized.

@gitar-bot

This comment has been minimized.

@gitar-bot gitar-bot Bot added the gitar-approved Added by Gitar label Aug 6, 2026

@gitar-bot gitar-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gitar has auto-approved this PR and enabled auto-merge (configure)

@hyperpolymath
hyperpolymath merged commit 7ce8399 into main Aug 7, 2026
2 of 5 checks passed
@hyperpolymath
hyperpolymath deleted the chore/gitleaks-allowlist branch August 7, 2026 10:58
@sonarqubecloud

sonarqubecloud Bot commented Aug 7, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gitar-approved Added by Gitar

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant