21 lines
1.4 KiB
JSON
21 lines
1.4 KiB
JSON
|
|
{
|
||
|
|
"suppressions": [
|
||
|
|
{
|
||
|
|
"id": "gitleaks-generic-api-key-2",
|
||
|
|
"justification": "False positive. .env.example line 2 is a documented placeholder env var (empty/inert value) that exists to show the required variable shape. gitleaks runs in git-mode and scans committed history, so it flags the placeholder even though the working-tree value is not a live secret. No real credential is or was exposed."
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "gitleaks-private-key-128",
|
||
|
|
"justification": "False positive. agent-team/scripts/assert_no_write_token.py is the no-write-token DETECTOR: it must reference a PEM begin-marker for a private key in order to find leaked keys. Source assembles the marker at runtime, but gitleaks scans committed history where an earlier contiguous-literal residual flags. Not a live key. (agent-team decommissioned 2026-06-26; entry kept for the history scan.)"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "gitleaks-private-key-30",
|
||
|
|
"justification": "False positive. Synthetic/redacted PEM fixture in agent-team/tests/test_no_write_token.py used to exercise the no-write-token audit; not a live key. Flagged only because gitleaks scans committed history."
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "gitleaks-private-key-34",
|
||
|
|
"justification": "False positive. Second synthetic/redacted PEM fixture in agent-team/tests/test_no_write_token.py; not a live key. Flagged only because gitleaks scans committed history."
|
||
|
|
}
|
||
|
|
]
|
||
|
|
}
|