Skip to content

gitleaks allowlist is 100% stale — all 6 paths point at files that don't exist in this repo #406

Description

@wz-gsa

Finding (backlog grooming, verified against current main)

`.gitleaks.toml`'s `[allowlist]` block exempts 6 paths, intended for documented example secrets / deliberate test fixtures. All six are absent from this repo's tree:

```
docs/explorations/downscoping-github-credentials-for-local-agents.md
docs/getting-started.md
docs/safety-guidance.md
docs/test-cases-schema.md
.agents/skills/secure-code-review/tests/*
scripts/tests/test_validate_sensitive_terms.py
test/sandbox-unit.sh
```

Verified with `find . -iname ""` for each — zero matches, repo-wide, excluding `node_modules`/`.git`. These read like paths copied from the patterns repo's config (which does have a `secure-code-review` skill and a `test_validate_sensitive_terms.py`), not this repo's actual tree.

Impact

A full-history gitleaks scan of this repo gets no functional allowlist — every exemption is inert. If any file matching one of those literal (non-existent) names is ever added, it would be silently exempted without anyone having reviewed whether that's still appropriate; more importantly, whatever files in THIS repo actually need the exemption (if any) are currently unprotected.

Fix

Either:

  1. Remove the dead allowlist entirely if this repo has no files needing a documented-secret exemption today, or
  2. Replace the paths with this repo's actual equivalents, if the intent was e.g. `docs/QUICKSTART.md`/`docs/KNOWN_FAILURE_MODES.md` (which do contain illustrative placeholder secrets) — needs a maintainer decision on which files genuinely need the exemption.

Low urgency (gitleaks' base ruleset still runs; this is a missing convenience allowlist, not a missing scan), but it's a security-tooling correctness gap worth fixing rather than leaving decorative.

AI-assisted (OpenCode), found during backlog grooming.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions