chore: suppress test-fixture credential false positive in token-TTL tests

Add a machine-level suppression for the fake "ghp_secret" GitHub token used by
the cached-token TTL/revocation unit tests (CWE-798). Not a real credential and
not a valid PAT; scoped to the unit test only.
This commit is contained in:
Adam Moussa 2026-06-29 12:14:49 -04:00
parent 8552e871f4
commit 5a0793bd35
No known key found for this signature in database

View file

@ -45,6 +45,19 @@
"suppression_justification": "Test fixture, not a real credential. Same fake Datadog API key \"secret-api-1234\" passed into connect_datadog by test_datadog_roundtrip_and_redaction. Never a live secret; scoped to the unit test only.",
"owner": "adam@seahavenind.com",
"added": "2026-06-29"
},
{
"id": "gitleaks-generic-api-key-23",
"title": "Hardcoded credential flagged in GitHub-token TTL test fixture (CWE-798)",
"file": "tests/test_github_token_ttl.py",
"line": 23,
"rule": "CWE-798",
"severity": "high",
"status": "false-positive",
"justification": "Test fixture, not a real credential. The literal \"ghp_secret\" is a fake GitHub token used by the cached-token TTL/revocation unit tests to exercise cache_github_token_for_thread / get_github_token expiry and invalidation. It is not a valid 40-char GitHub PAT, is never a live secret, and is scoped to the unit test only. Pre-existing test fixture, not introduced by this change.",
"suppression_justification": "Test fixture, not a real credential. The literal \"ghp_secret\" is a fake GitHub token used by the cached-token TTL/revocation unit tests to exercise cache_github_token_for_thread / get_github_token expiry and invalidation. It is not a valid 40-char GitHub PAT, is never a live secret, and is scoped to the unit test only. Pre-existing test fixture, not introduced by this change.",
"owner": "adam@seahavenind.com",
"added": "2026-06-29"
}
]
}