Suppress orchestrator's own .env.example gitleaks false positive
gitleaks git-mode scans committed history, so the .env.example placeholder flags from history and would block the orchestrator's own pre-push gate. Suppress it with a written justification. Also gitignore stray .adf_final*.json left by an unrelated tool.
This commit is contained in:
parent
537e83975b
commit
af5ce7362e
2 changed files with 11 additions and 0 deletions
3
.gitignore
vendored
3
.gitignore
vendored
|
|
@ -7,3 +7,6 @@ __pycache__/
|
||||||
.pytest_cache/
|
.pytest_cache/
|
||||||
.ruff_cache/
|
.ruff_cache/
|
||||||
.DS_Store
|
.DS_Store
|
||||||
|
|
||||||
|
# Stray Atlassian Document Format exports left by an unrelated tool — not part of this repo.
|
||||||
|
.adf_final*.json
|
||||||
|
|
|
||||||
8
.security-review/suppressions.json
Normal file
8
.security-review/suppressions.json
Normal file
|
|
@ -0,0 +1,8 @@
|
||||||
|
{
|
||||||
|
"suppressions": [
|
||||||
|
{
|
||||||
|
"id": "gitleaks-generic-api-key-2",
|
||||||
|
"justification": "False positive. .env.example:2 is a documented placeholder token (not a live secret) that exists to show the required env var shape. gitleaks runs in git-mode and scans committed history, so it flags the placeholder even though the working-tree value is inert. No real credential is or was exposed. Reviewed 2026-06-16."
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
Reference in a new issue