Add gitleaks config to allowlist test files
Ignores backend/tests/*.py across all git history to avoid false positives on variable names like 's3_key' in test assertions.
This commit is contained in:
8
.gitleaks.toml
Normal file
8
.gitleaks.toml
Normal file
@@ -0,0 +1,8 @@
|
|||||||
|
# Gitleaks configuration
|
||||||
|
# https://github.com/gitleaks/gitleaks#configuration
|
||||||
|
|
||||||
|
[allowlist]
|
||||||
|
# Test files that contain variable names matching secret patterns (e.g., s3_key)
|
||||||
|
paths = [
|
||||||
|
'''backend/tests/.*\.py''',
|
||||||
|
]
|
||||||
@@ -11,7 +11,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
|||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
- Fixed production CI deployment namespace to use correct `orch-namespace` (#54)
|
- Fixed production CI deployment namespace to use correct `orch-namespace` (#54)
|
||||||
- Added gitleaks fingerprint for test file false positive (#54)
|
- Added gitleaks config to allowlist test files from secret scanning (#54)
|
||||||
|
|
||||||
## [0.5.0] - 2026-01-23
|
## [0.5.0] - 2026-01-23
|
||||||
### Added
|
### Added
|
||||||
|
|||||||
Reference in New Issue
Block a user