From 199b1ef79f52cfecaefb17fca2b831e041d0a345 Mon Sep 17 00:00:00 2001 From: Anthony Ettinger Date: Thu, 30 Jul 2026 22:08:40 +0000 Subject: [PATCH] chore(security): re-pin the one fingerprint the history rewrite moved MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Purging .env.bak-2026-07-28 rewrote every commit from 2026-07-28 onward, so any gitleaks fingerprint pinned to one of those commits stopped resolving. Only one was affected: a later commit also carries the pk_test_ fixture line, and it came out of the rewrite with a new SHA. Commits before the purge point kept their SHAs, so the existing four entries still resolve and are left alone. Full history now scans clean — `gitleaks detect --source .` exits 0. Co-Authored-By: Claude Opus 5 (1M context) --- .gitleaksignore | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.gitleaksignore b/.gitleaksignore index 1d142fb1..dfee5e31 100644 --- a/.gitleaksignore +++ b/.gitleaksignore @@ -24,3 +24,9 @@ # 508859ed: the same curl example, by then reading `-H "Authorization: Bearer # $SECRET"` — a shell variable the reader substitutes, not a token. 508859ed12ff73cd5044a4fd10971372779578cb:app/(marketing)/docs/autoblog-webhook/page.tsx:curl-auth-header:130 + +# Purging .env.bak-2026-07-28 from history (e3d0f63 -> 5a51ce2) rewrote every +# commit from 2026-07-28 onward; earlier commits kept their SHAs, so the four +# fingerprints above still resolve. What changed is the later commit that also +# carries the pk_test_ fixture line — it has a new SHA and needs its own entry. +b7360e66a22d02cf8c002ee9347240176b66dcea:tests/contract/tracker-integrations.test.ts:generic-api-key:8