Repository navigation
chore(security): make the main-branch gitleaks scan green again - #4033
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
20fcbd3 to
a86d73e
Compare
|
Verified against main’s latest failed scan, 35922969389: its two findings exactly match these fingerprints. The referenced values are an intentional redaction-test fixture and a truncated README JWT placeholder. These exclusions are narrowly scoped, and current PR checks pass. This looks ready for code-owner approval. |
|
liamcrumm Prayag (@prayagupa) this needs a code-owner review. It only adds two |
The Secret Scanning workflow has failed on every push and scheduled run on main since 2026-07-30. Its non-PR mode scans the full history, and two historic commits trip it: - 33eeccb (squash merge of #3955) carries the test fixture sk-abcdefghijklmnopqrstuvwxyz0123 in agent-governance-python/agent-os/tests/test_mcp_pii_and_response_gateway.py. The fingerprint added in that PR names the pre-squash commit 4013555, which is not in main's history. - 2c43622 (#2399) carries a placeholder JWT in the cedarling-agentmesh README. Its fingerprint was dropped from .gitleaksignore by #3444 on 2026-07-30, and the file itself was deleted by #3451, so only the historic commit remains. Add the two fingerprints for the commits that are actually on main and drop the dead pre-squash line. Verified with gitleaks 8.24.3: a full history scan of main reports no leaks with these lines and exactly the two findings without them. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
a86d73e to
ea1d612
Compare
…osoft#4033) The Secret Scanning workflow has failed on every push and scheduled run on main since 2026-07-30. Its non-PR mode scans the full history, and two historic commits trip it: - 33eeccb (squash merge of microsoft#3955) carries the test fixture sk-abcdefghijklmnopqrstuvwxyz0123 in agent-governance-python/agent-os/tests/test_mcp_pii_and_response_gateway.py. The fingerprint added in that PR names the pre-squash commit 4013555, which is not in main's history. - 2c43622 (microsoft#2399) carries a placeholder JWT in the cedarling-agentmesh README. Its fingerprint was dropped from .gitleaksignore by microsoft#3444 on 2026-07-30, and the file itself was deleted by microsoft#3451, so only the historic commit remains. Add the two fingerprints for the commits that are actually on main and drop the dead pre-squash line. Verified with gitleaks 8.24.3: a full history scan of main reports no leaks with these lines and exactly the two findings without them. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com> Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Summary
The Secret Scanning workflow has failed on every push and scheduled run on main since 2026-07-30 (last green run: 2026-07-13). Its non-PR mode runs a full-history scan, and two historic commits trip it:
33eeccbc(squash merge of fix: credential redactor boundary anchors in TypeScript, Python and Rust (#3933) #3955) carries the test fixturesk-abcdefghijklmnopqrstuvwxyz0123inagent-governance-python/agent-os/tests/test_mcp_pii_and_response_gateway.py:343. The.gitleaksignorefingerprint added in that PR names the pre-squash commit40135558, which is not in main's history. fix(security): pin emitted and tutorial GitHub Actions to commit SHAs #3556's Secret Scanning run hit this today.2c436227(feat: add cedarling-agentmesh community integration and runnable example #2399) carries a placeholder JWT in the cedarling-agentmesh README. Its fingerprint was dropped from.gitleaksignoreby refactor(v4-removal)!: replace the v4 policy language with ACS v5 across the Python runtime #3444 on 2026-07-30 and the file itself was deleted by refactor(v4-removal)!: drop the cedarling backend and refresh the agentmesh integrations #3451, so only the historic commit remains.Changes
.gitleaksignore: add the two fingerprints for the commits that are on main; drop the dead pre-squash line.Testing
62c47122..HEADfrom this branch: no leaks.Notes
Fingerprints taken from PR commits die on squash merge;
.gitleaks.toml's header already warns about this. If it keeps recurring, the squash-safe alternative is a path entry in.gitleaks.tomlfor the test file. Secret Scanning is not in the ruleset's required checks, so this changes no merge gate; it only stops the daily red run.