Skip to content

chore(security): make the main-branch gitleaks scan green again - #4033

Merged
MohammadHaroonAbuomar merged 1 commit into
mainfrom
mhabuomar/gitleaksignore-3955
Sep 26, 2026
Merged

MohammadHaroonAbuomar merged 1 commit into
mainfrom
mhabuomar/gitleaksignore-3955

Conversation

@MohammadHaroonAbuomar

@MohammadHaroonAbuomar MohammadHaroonAbuomar commented Sep 18, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

The Secret Scanning workflow has failed on every push and scheduled run on main since 2026-07-30 (last green run: 2026-07-13). Its non-PR mode runs a full-history scan, and two historic commits trip it:

Changes

  • .gitleaksignore: add the two fingerprints for the commits that are on main; drop the dead pre-squash line.

Testing

  • gitleaks 8.24.3 full-history scan of main: no leaks with these lines, exactly the two findings without them.
  • Range scan 62c47122..HEAD from this branch: no leaks.

Notes

Fingerprints taken from PR commits die on squash merge; .gitleaks.toml's header already warns about this. If it keeps recurring, the squash-safe alternative is a path entry in .gitleaks.toml for the test file. Secret Scanning is not in the ruleset's required checks, so this changes no merge gate; it only stops the daily red run.

@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions github-actions Bot added the size/XS Extra small PR (< 10 lines) label Sep 18, 2026
@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@MohammadHaroonAbuomar
MohammadHaroonAbuomar force-pushed the mhabuomar/gitleaksignore-3955 branch from 20fcbd3 to a86d73e Compare September 18, 2026 18:07
@MohammadHaroonAbuomar MohammadHaroonAbuomar changed the title chore(security): allowlist the squashed #3955 test fixture for gitleaks chore(security): make the main-branch gitleaks scan green again Sep 18, 2026
@imran-siddique

Copy link
Copy Markdown
Collaborator

Verified against main’s latest failed scan, 35922969389: its two findings exactly match these fingerprints. The referenced values are an intentional redaction-test fixture and a truncated README JWT placeholder. These exclusions are narrowly scoped, and current PR checks pass. This looks ready for code-owner approval.

@MohammadHaroonAbuomar

Copy link
Copy Markdown
Collaborator Author

liamcrumm Prayag (@prayagupa) this needs a code-owner review. It only adds two .gitleaksignore fingerprints for historical commits, and it is what turns the main-branch Secret Scanning workflow green again (red since July). Rebased onto current main; all checks pass.

The Secret Scanning workflow has failed on every push and scheduled run
on main since 2026-07-30. Its non-PR mode scans the full history, and two
historic commits trip it:

- 33eeccb (squash merge of #3955) carries the test fixture
  sk-abcdefghijklmnopqrstuvwxyz0123 in
  agent-governance-python/agent-os/tests/test_mcp_pii_and_response_gateway.py.
  The fingerprint added in that PR names the pre-squash commit 4013555,
  which is not in main's history.
- 2c43622 (#2399) carries a placeholder JWT in the cedarling-agentmesh
  README. Its fingerprint was dropped from .gitleaksignore by #3444 on
  2026-07-30, and the file itself was deleted by #3451, so only the
  historic commit remains.

Add the two fingerprints for the commits that are actually on main and
drop the dead pre-squash line. Verified with gitleaks 8.24.3: a full
history scan of main reports no leaks with these lines and exactly the
two findings without them.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
@MohammadHaroonAbuomar
MohammadHaroonAbuomar force-pushed the mhabuomar/gitleaksignore-3955 branch from a86d73e to ea1d612 Compare September 24, 2026 10:16
@MohammadHaroonAbuomar
MohammadHaroonAbuomar merged commit 4b1d5be into main Sep 26, 2026
95 checks passed
@MohammadHaroonAbuomar
MohammadHaroonAbuomar deleted the mhabuomar/gitleaksignore-3955 branch September 26, 2026 00:54
Yuvraj Singh (yuvrajsingh2428) pushed a commit to yuvrajsingh2428/agent-governance-toolkit that referenced this pull request Oct 1, 2026
…osoft#4033)

The Secret Scanning workflow has failed on every push and scheduled run
on main since 2026-07-30. Its non-PR mode scans the full history, and two
historic commits trip it:

- 33eeccb (squash merge of microsoft#3955) carries the test fixture
  sk-abcdefghijklmnopqrstuvwxyz0123 in
  agent-governance-python/agent-os/tests/test_mcp_pii_and_response_gateway.py.
  The fingerprint added in that PR names the pre-squash commit 4013555,
  which is not in main's history.
- 2c43622 (microsoft#2399) carries a placeholder JWT in the cedarling-agentmesh
  README. Its fingerprint was dropped from .gitleaksignore by microsoft#3444 on
  2026-07-30, and the file itself was deleted by microsoft#3451, so only the
  historic commit remains.

Add the two fingerprints for the commits that are actually on main and
drop the dead pre-squash line. Verified with gitleaks 8.24.3: a full
history scan of main reports no leaks with these lines and exactly the
two findings without them.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/XS Extra small PR (< 10 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants