Skip to content

chore(security): re-pin the one fingerprint the history rewrite moved - #169

Merged
ralyodio merged 1 commit into
masterfrom
fix/gitleaksignore-post-rewrite
Jul 30, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix/gitleaksignore-post-rewrite

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Follow-up to the history scrub. master went e3d0f63 → 5a51ce2 when .env.bak-2026-07-28 was purged with git filter-repo.

A gitleaks fingerprint pins a commit SHA, and the rewrite changed the SHA of every commit from 2026-07-28 onward. Commits before that point kept their SHAs, so the four existing entries still resolve and are untouched. One later commit also carries the pk_test_ fixture line and came out of the rewrite with a new SHA — that's the single entry added here.

Verification: gitleaks detect --source . over full history now reports no leaks found, exit 0. Before this commit it reported 1.

Nothing real is suppressed. The 21 credentials are gone from every commit rather than hidden — git log --all -- .env.bak-2026-07-28 returns nothing, a fresh clone from GitHub has 0 references, and GitHub refuses to serve the old commit (upload-pack: not our ref).

🤖 Generated with Claude Code

Purging .env.bak-2026-07-28 rewrote every commit from 2026-07-28 onward, so any
gitleaks fingerprint pinned to one of those commits stopped resolving. Only one
was affected: a later commit also carries the pk_test_ fixture line, and it came
out of the rewrite with a new SHA. Commits before the purge point kept their
SHAs, so the existing four entries still resolve and are left alone.

Full history now scans clean — `gitleaks detect --source .` exits 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio merged commit 540e7e3 into master Jul 30, 2026
8 checks passed
@ralyodio
ralyodio deleted the fix/gitleaksignore-post-rewrite branch July 30, 2026 22:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant