Suppress orchestrator's own .env.example gitleaks false positive

gitleaks git-mode scans committed history, so the .env.example placeholder flags from
history and would block the orchestrator's own pre-push gate. Suppress it with a written
justification. Also gitignore stray .adf_final*.json left by an unrelated tool.
This commit is contained in:
Adam Moussa 2026-06-16 15:00:00 -04:00
parent 537e83975b
commit af5ce7362e
2 changed files with 11 additions and 0 deletions

3
.gitignore vendored
View file

@ -7,3 +7,6 @@ __pycache__/
.pytest_cache/
.ruff_cache/
.DS_Store
# Stray Atlassian Document Format exports left by an unrelated tool — not part of this repo.
.adf_final*.json

View file

@ -0,0 +1,8 @@
{
"suppressions": [
{
"id": "gitleaks-generic-api-key-2",
"justification": "False positive. .env.example:2 is a documented placeholder token (not a live secret) that exists to show the required env var shape. gitleaks runs in git-mode and scans committed history, so it flags the placeholder even though the working-tree value is inert. No real credential is or was exposed. Reviewed 2026-06-16."
}
]
}