Allowlist the fake Stripe test fixture in gitleaks - #417
Conversation
Gemini PR ReviewReviewed commit:
This result blocks merge. Push a fix and comment |
|
/gemini review |
Gemini PR ReviewReviewed commit: |
3585fb0 to
d8e089c
Compare
Gemini PR ReviewReviewed commit: |
|
/gemini review |
Gemini PR ReviewReviewed commit: No actionable findings. |
…lag the config file
|
/gemini review |
Gemini PR ReviewReviewed commit:
This result blocks merge. Push a fix and comment |
|
/gemini dispute
|
|
/gemini review |
Gemini PR ReviewReviewed commit:
|
Fake Stripe keys used as fixtures in
governance/billing_readiness_test.goandtools/httpserver/billing_handler_test.go(on the use-joltrinhq-domain branch) trip thestripe-access-tokenrule. The CI job scans every ref, so that fails Gitleaks on every PR and on master's scheduled Security run.Adds the exact literal
sk_test_placeholderto the regex allowlist, next to the existing fixture entries likelegacy-secret. Every one of the 11 findings is that string.An earlier revision loosened the test-file path pattern instead. Gemini flagged that as too broad, since it would skip every Go test file for every rule, so it was dropped.
Checked:
gitleaks detect --config .gitleaks.tomlover all refs went from 11 findings to none. A realistic-lookingsk_test_...key in a_test.gofile is still flagged.Thanks, Gerard Recinto