mirror of
https://github.com/akitaonrails/ai-memory.git
synced 2026-10-02 03:24:46 +08:00
test(sanitize): exempt the new credential fixtures from the secret scan
The fixtures added in #408 are key-shaped by construction — that is the point of a sanitizer test — so gitleaks flagged the Stripe restricted-key and Telegram bot-token cases and failed CI. Exempt exactly those literals, per the fail-closed rule this file already states: specific strings with a rationale, never a path exclusion. The Telegram example is listed twice because gitleaks matches an allowlist against the secret a rule extracted, and `generic-api-key` extracts only the tail after the colon. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
d869efd4a7
commit
4ee9bcba23
@@ -40,6 +40,17 @@ regexes = [
|
||||
'''ghp_FAKE[A-Z0-9]+''',
|
||||
'''github_pat_FAKE[A-Z0-9_]+''',
|
||||
'''AKIAFAKE[A-Z0-9]+''',
|
||||
'''ASIAFAKE[A-Z0-9]+''',
|
||||
# Stripe *restricted* key fixture, same FAKE convention as the keys above.
|
||||
'''rk_live_FAKEfake[A-Za-z0-9]+''',
|
||||
# Telegram bot-token fixture: the example Telegram itself publishes in its
|
||||
# Bot API documentation — a shape anyone can look up, not an issued token.
|
||||
# The sanitizer test asserts that exact documented form is redacted.
|
||||
# Listed twice on purpose: gitleaks matches an allowlist against the
|
||||
# secret a rule *extracted*, and `generic-api-key` extracts only the tail
|
||||
# after the colon, so the full-token form alone would not exempt it.
|
||||
'''123456:ABC-DEF1234ghIkl-zyx57W2v1u123ew11''',
|
||||
'''ABC-DEF1234ghIkl-zyx57W2v1u123ew11''',
|
||||
'''Bearer abcdef0123456789ABCDEF0123456789''',
|
||||
'''xoxb-1234567890-abcdefghij''',
|
||||
|
||||
|
||||
Reference in New Issue
Block a user