Suppress orchestrator's own .env.example gitleaks false positive
gitleaks git-mode scans committed history, so the .env.example placeholder flags from history and would block the orchestrator's own pre-push gate. Suppress it with a written justification. Also gitignore stray .adf_final*.json left by an unrelated tool.
This commit is contained in:
parent
537e83975b
commit
af5ce7362e
2 changed files with 11 additions and 0 deletions
3
.gitignore
vendored
3
.gitignore
vendored
|
|
@ -7,3 +7,6 @@ __pycache__/
|
|||
.pytest_cache/
|
||||
.ruff_cache/
|
||||
.DS_Store
|
||||
|
||||
# Stray Atlassian Document Format exports left by an unrelated tool — not part of this repo.
|
||||
.adf_final*.json
|
||||
|
|
|
|||
8
.security-review/suppressions.json
Normal file
8
.security-review/suppressions.json
Normal file
|
|
@ -0,0 +1,8 @@
|
|||
{
|
||||
"suppressions": [
|
||||
{
|
||||
"id": "gitleaks-generic-api-key-2",
|
||||
"justification": "False positive. .env.example:2 is a documented placeholder token (not a live secret) that exists to show the required env var shape. gitleaks runs in git-mode and scans committed history, so it flags the placeholder even though the working-tree value is inert. No real credential is or was exposed. Reviewed 2026-06-16."
|
||||
}
|
||||
]
|
||||
}
|
||||
Reference in a new issue