mirror of
https://github.com/akitaonrails/ai-memory.git
synced 2026-10-02 03:24:46 +08:00
The full-history secret scan flagged two auth-header test fixtures added by PR #598 (sanitize.rs:631,633) — a realistic-looking UUID and a base64 token, which have high enough entropy to trip gitleaks' generic-api-key rule. They are synthetic values in the test that asserts NON-secret headers are left alone, not real secrets. Two changes: add their historical fingerprints to .gitleaksignore (the repo's mechanism for known test-fixture findings, matching the existing sibling entries), and lower the current fixtures to the low-entropy "obvious fake" shape the other sanitize fixtures use (per .gitleaks.toml) so future copies of the pattern do not re-trip the scan. The test is name-based, so the value shape does not change what it asserts. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm
10 lines
863 B
Plaintext
10 lines
863 B
Plaintext
6004869ea350546a8aefcf1237895e708cc51557:crates/ai-memory-cli/src/commands/hook.rs:generic-api-key:389
|
|
16e87742aeb51ac34a44f71392b05579865e9b9e:crates/ai-memory-wiki/src/wiki.rs:github-pat:1719
|
|
a861ec3d598885d43500713d21d4e1aafbf46645:tests/e2e/handoff_smoke.sh:curl-auth-header:188
|
|
747c32d50f824cae665f2e35bbd62c8502438903:crates/ai-memory-hooks/src/sanitize.rs:generic-api-key:125
|
|
747c32d50f824cae665f2e35bbd62c8502438903:crates/ai-memory-hooks/src/sanitize.rs:jwt:107
|
|
d8361d3c3a86f870f74841b53c568c64fe42ab1f:crates/ai-memory-core/src/sanitize.rs:gcp-api-key:226
|
|
d8361d3c3a86f870f74841b53c568c64fe42ab1f:crates/ai-memory-core/src/sanitize.rs:generic-api-key:257
|
|
47c9cf2e71712153e3162942a8cb28667a6be27a:crates/ai-memory-core/src/sanitize.rs:generic-api-key:631
|
|
47c9cf2e71712153e3162942a8cb28667a6be27a:crates/ai-memory-core/src/sanitize.rs:generic-api-key:633
|