The no-write-token detector's test fixtures + a doc comment contained contiguous '-----BEGIN ... PRIVATE KEY-----' literals that tripped the repo's gitleaks pre-push backstop (a false positive on a secret-DETECTOR's own test data). Build the PEM markers at runtime so the source carries no contiguous literal; the runtime values are still full PEM blocks (what the detector under test sees). No behavior change; 39 no-write-token tests pass. |
||
|---|---|---|
| .. | ||
| assert_no_write_token.py | ||
| deploy-r720-ws-rollout.sh | ||
| deploy-r720.sh | ||
| p3_rollback.sh | ||