Skip to content

fix(ci): allowlist test fixtures and doc examples in gitleaks config - #645

Merged
d-oit merged 2 commits into
mainfrom
fix/gitleaks-allowlist-false-positives
Aug 11, 2026
Merged

fix(ci): allowlist test fixtures and doc examples in gitleaks config#645
d-oit merged 2 commits into
mainfrom
fix/gitleaks-allowlist-false-positives

Conversation

@d-oit

@d-oit d-oit commented Aug 11, 2026

Copy link
Copy Markdown
Owner

Extends the gitleaks allowlist to cover 8 false positives surfaced after the v2.3.9 pin enabled real scanning:

  • test fixture keys (e.g. test-api-key-123456789)
  • historical test files (src/lib/llm/tests/) removed from main but scanned via full history
  • doc examples in security-patterns.md (sk-abc123xyz, fake RSA key)
  • SKILL.md env-var placeholder line

Verified with the manual security-scan run (31526331570).

@vercel

vercel Bot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
do-knowledge-studio Ready Ready Preview, v0 Aug 11, 2026 7:18pm

@deepsource-io

deepsource-io Bot commented Aug 11, 2026

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in da28c50...8860686 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
JavaScript Aug 11, 2026 7:17p.m. Review ↗
Python Aug 11, 2026 7:17p.m. Review ↗
Shell Aug 11, 2026 7:17p.m. Review ↗
SQL Aug 11, 2026 7:17p.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@codacy-production

Copy link
Copy Markdown
Contributor

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@d-oit
d-oit merged commit 6ef98fa into main Aug 11, 2026
27 checks passed
@d-oit
d-oit deleted the fix/gitleaks-allowlist-false-positives branch August 11, 2026 19:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant