Skip to content

Allowlist the fake Stripe test fixture in gitleaks - #417

Merged
gerardrecinto merged 3 commits into
masterfrom
fix-gitleaks-test-file-allowlist
Oct 2, 2026
Merged

gerardrecinto merged 3 commits into
masterfrom
fix-gitleaks-test-file-allowlist

Conversation

@gerardrecinto

@gerardrecinto gerardrecinto commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Fake Stripe keys used as fixtures in governance/billing_readiness_test.go and tools/httpserver/billing_handler_test.go (on the use-joltrinhq-domain branch) trip the stripe-access-token rule. The CI job scans every ref, so that fails Gitleaks on every PR and on master's scheduled Security run.

Adds the exact literal sk_test_placeholder to the regex allowlist, next to the existing fixture entries like legacy-secret. Every one of the 11 findings is that string.

An earlier revision loosened the test-file path pattern instead. Gemini flagged that as too broad, since it would skip every Go test file for every rule, so it was dropped.

Checked: gitleaks detect --config .gitleaks.toml over all refs went from 11 findings to none. A realistic-looking sk_test_... key in a _test.go file is still flagged.

Thanks, Gerard Recinto

@gerardrecinto gerardrecinto self-assigned this Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Gemini PR Review

Reviewed commit: 9827fd45c000f986ad76a3a6f300b8163f4b2169
Verdict: FAIL

  • Security Problem: In .gitleaks.toml, the change from (^|/)_test\.go$ to _test\.go$ in the allowlist significantly broadens the scope of files ignored by the gitleaks secret scanner. The new regular expression matches any file ending with _test.go, which includes common Go test file naming conventions like main_test.go or util_test.go. Previously, gitleaks would have scanned such files for secrets. This change weakens the secret scanning coverage, potentially allowing secrets committed within test files to go undetected.

This result blocks merge. Push a fix and comment /gemini review. To contest a finding, see the Gemini dispute process in CONTRIBUTING.md.

@gerardrecinto gerardrecinto changed the title Fix the gitleaks test-file allowlist regex Allowlist the fake Stripe test fixture in gitleaks Oct 2, 2026
@gerardrecinto

Copy link
Copy Markdown
Collaborator Author

/gemini review

Comment thread .gitleaks.toml Fixed
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Gemini PR Review

Reviewed commit: 3585fb00e9f667567847d38ddb6add7e29893f6d
Verdict: PASS

@gerardrecinto
gerardrecinto force-pushed the fix-gitleaks-test-file-allowlist branch from 3585fb0 to d8e089c Compare October 2, 2026 05:33
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Gemini PR Review

Reviewed commit: d8e089c41deea83ebce7262aa8b2ddbcc74c257d
Verdict: PASS

@gerardrecinto

Copy link
Copy Markdown
Collaborator Author

/gemini review

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Gemini PR Review

Reviewed commit: d8e089c41deea83ebce7262aa8b2ddbcc74c257d
Verdict: PASS

No actionable findings.

@gerardrecinto

Copy link
Copy Markdown
Collaborator Author

/gemini review

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Gemini PR Review

Reviewed commit: 6fb7ebfce717a19b9fba7680c644f7835507c912
Verdict: FAIL

  • .gitleaks.toml: The change adds '''sk_test_placehold[e]r''' to the regexes list. The accompanying comment states, "Fake Stripe key used as a fixture in the billing tests." Entries in the regexes section of .gitleaks.toml define patterns that Gitleaks should detect as secrets. If the intent is to allow this specific string (e.g., sk_test_placeholder) as a fake fixture and prevent Gitleaks from flagging it as a secret, this pattern should be added to the allowlist.regexes section or excluded by path, not the regexes section. As implemented, Gitleaks will flag any occurrence of sk_test_placeholder, which contradicts the stated purpose of it being a fake fixture and could lead to unnecessary security alerts or alert fatigue.

This result blocks merge. Push a fix and comment /gemini review. To contest a finding, see the Gemini dispute process in CONTRIBUTING.md.

@gerardrecinto

Copy link
Copy Markdown
Collaborator Author

/gemini dispute

  1. Finding, quoted: "Entries in the regexes section of .gitleaks.toml define patterns that Gitleaks should detect as secrets ... this pattern should be added to the allowlist.regexes section or excluded by path, not the regexes section."

  2. Location: .gitleaks.toml, the added entry '''sk_test_placehold[e]r'''.

  3. Claim type: Observed, and it is incorrect. The review read the list as a top-level custom-rule list. It is not.

  4. Evidence: in this file regexes = [ is declared after the [allowlist] table header and before any other table, so TOML places it at allowlist.regexes. The file has no top-level regexes. Parsed with Python tomllib: top-level keys are title, extend, allowlist; keys under allowlist are description, paths, regexes; and 'sk_test_placehold[e]r' in allowlist['regexes'] is True. The new entry sits in the same list as the existing allowlist entries legacy-secret, my-secret-token, and the Azure role IDs. The previous commit on this PR (d8e089c4) used the same structure and got verdict=PASS for it.

  5. Docs: Gitleaks configuration, global [allowlist] with paths and regexes: https://github.com/gitleaks/gitleaks#configuration

  6. Reachability: the entry only suppresses Gitleaks findings whose matched text matches sk_test_placehold[e]r. It cannot cause a detection. A real-looking sk_test_ key is not matched by it and is still reported.

  7. Reproduction: gitleaks detect --config .gitleaks.toml over all refs: 11 findings on master's config, 0 with this change. A probe file probe_test.go containing a realistic sk_test_ key is still reported by the same config ("leaks found: 1"). Separately, Trivy's secret scanner flagged the previous literal form of this entry as a Stripe key, which is why it is written with the bracket.

  8. Compensating control: none needed. The pattern is narrow, and real keys in test or non-test files are still caught.

  9. Resolution requested: withdraw the finding and return PASS on the current commit.

@gerardrecinto

Copy link
Copy Markdown
Collaborator Author

/gemini review

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Gemini PR Review

Reviewed commit: 6fb7ebfce717a19b9fba7680c644f7835507c912
Verdict: PASS

  • No actionable findings. The addition of '''sk_test_placehold[e]r''' to the .gitleaks.toml file is correctly placed within the allowlist.regexes section. The prior finding incorrectly assumed this entry was in a top-level regexes section, which would define a custom detection rule, not an allowlist. However, the TOML structure of the file, confirmed by the dispute's evidence and the implied context of the diff, places this regexes = [ array under the [allowlist] table. This entry thus serves to suppress Gitleaks findings for a specific, narrow pattern, as intended for a test fixture, without weakening security for actual secrets.

@gerardrecinto
gerardrecinto merged commit 87956e8 into master Oct 2, 2026
23 of 24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants