Conversation
`gitleaks detect` scans history, so the 21 findings from the environment backup committed in cfb23d2 (#160) keep failing the scan no matter what HEAD contains — untracking the file did nothing for them. The alternative is rewriting master to drop the blob, which forces all 8 collaborators to re-clone and still leaves the objects on GitHub's servers. Appended to the existing ignore list rather than replacing it; the two false-positive pins already there (the docs placeholder and the tracker test fixture) are untouched. These 21 differ from those two in kind: the values were real, not false positives. Pinning them is only honest after rotation, since rotation is what makes the recorded values dead. The file says so, at length, where the next person to read it will see it. Verified against a pristine clone of master with gitleaks 8.21.2 — the same version CI installs: 21 findings before, "no leaks found" after. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
ralyodio
force-pushed
the
worktree-gitleaks-ignore
branch
from
July 30, 2026 22:05
51af7c9 to
99a5586
Compare
Contributor
Author
|
Superseded: the history was scrubbed. There is nothing left for this PR to pin, and it now conflicts. The two genuine false positives are handled separately — note that the rewrite invalidated every existing fingerprint, since a fingerprint pins a commit SHA. Credential rotation is still required: removing the blob does not un-publish what was already exposed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Draft on purpose — this should not merge until the credentials are rotated. See "Why this is a draft" below.
Pairs with #166 (which untracks the file). Independent of it; either can land first.
The problem
gitleaks detect --source .scans history, so untracking the environment backup did nothing for the check — it still reports the original commit,925da5e(#160), 21 findings, on every PR in this repo.Three ways out: rewrite history, pin the findings, or narrow the workflow. Rewriting means a force-push to
master, all 8 collaborators re-cloning, invalidated open PRs, and a rewrittenv0.2.0tag — and it still doesn't remove the objects from GitHub's servers (verified: a commit remains fetchable via the API after its branch is deleted). Pinning is the documented mechanism for exactly this situation.What this does
Appends the 21 fingerprints to the existing
.gitleaksignore. The two entries already there — thecurl-auth-headerdocs placeholder and the tracker-testpk_test_fixture — are preserved untouched, along with their explanatory comments.Each pin is scoped to
<commit>:<file>:<rule>:<line>, so it silences only these specific historical findings. A new leak anywhere still fails the scan — this does not blanket-disable the check.Why this is a draft
The two pre-existing entries are genuine false positives — placeholder strings that were never secret. These 21 are not. The values were real. Pinning them is only defensible once they've been rotated, because rotation is what turns the recorded values into dead data and makes the finding genuinely stale.
Merged before rotation, this file suppresses an alarm about a live exposure. The file says so in a comment block, so whoever reads it next sees the condition attached. Mark ready and merge once rotation is done.
Verification
Run against a pristine clone of
masterwith gitleaks 8.21.2 — the exact version.github/workflows/security.ymlinstalls:.env.bak-2026-07-28@925da5e)INF no leaks found, exit 0Worth noting the check is
continue-on-error: true, so it has been reporting failure without blocking merges. This turns the signal back on rather than unblocking anything.🤖 Generated with Claude Code