Files
ai-memory/.gitleaksignore
T
AkitaOnRailsandClaude Fable 5 dc11fd4106 chore(gitleaks): allowlist #598's sanitize test fixtures
The full-history secret scan flagged two auth-header test fixtures added
by PR #598 (sanitize.rs:631,633) — a realistic-looking UUID and a base64
token, which have high enough entropy to trip gitleaks' generic-api-key
rule. They are synthetic values in the test that asserts NON-secret
headers are left alone, not real secrets.

Two changes: add their historical fingerprints to .gitleaksignore (the
repo's mechanism for known test-fixture findings, matching the existing
sibling entries), and lower the current fixtures to the low-entropy
"obvious fake" shape the other sanitize fixtures use (per .gitleaks.toml)
so future copies of the pattern do not re-trip the scan. The test is
name-based, so the value shape does not change what it asserts.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
2026-09-03 13:00:29 -03:00

10 lines
863 B
Plaintext

6004869ea350546a8aefcf1237895e708cc51557:crates/ai-memory-cli/src/commands/hook.rs:generic-api-key:389
16e87742aeb51ac34a44f71392b05579865e9b9e:crates/ai-memory-wiki/src/wiki.rs:github-pat:1719
a861ec3d598885d43500713d21d4e1aafbf46645:tests/e2e/handoff_smoke.sh:curl-auth-header:188
747c32d50f824cae665f2e35bbd62c8502438903:crates/ai-memory-hooks/src/sanitize.rs:generic-api-key:125
747c32d50f824cae665f2e35bbd62c8502438903:crates/ai-memory-hooks/src/sanitize.rs:jwt:107
d8361d3c3a86f870f74841b53c568c64fe42ab1f:crates/ai-memory-core/src/sanitize.rs:gcp-api-key:226
d8361d3c3a86f870f74841b53c568c64fe42ab1f:crates/ai-memory-core/src/sanitize.rs:generic-api-key:257
47c9cf2e71712153e3162942a8cb28667a6be27a:crates/ai-memory-core/src/sanitize.rs:generic-api-key:631
47c9cf2e71712153e3162942a8cb28667a6be27a:crates/ai-memory-core/src/sanitize.rs:generic-api-key:633