chore(security): add gitleaks config and update ignore list for test tokens

Co-authored-by: ivuorinen <11024+ivuorinen@users.noreply.github.com>
This commit is contained in:
copilot-swe-agent[bot]
2026-03-15 13:24:57 +00:00
parent 392d461100
commit a389fe3ef6
2 changed files with 17 additions and 0 deletions

14
.gitleaks.toml Normal file
View File

@@ -0,0 +1,14 @@
title = "gh-action-readme gitleaks configuration"
[extend]
useDefault = true
# Allowlist for test files and fixtures that intentionally contain placeholder tokens.
# These are not real secrets and are used only for testing purposes.
[[allowlists]]
description = "Test fixture files containing placeholder tokens"
paths = [
'''testutil/test_constants\.go''',
'''.*_test\.go''',
'''testdata/.*''',
]

View File

@@ -23,3 +23,6 @@ internal/wizard/validator_test.go:github-pat:204
integration_test.go:github-pat:304 integration_test.go:github-pat:304
internal/config_test.go:github-pat:133 internal/config_test.go:github-pat:133
internal/config_test.go:github-pat:162 internal/config_test.go:github-pat:162
testdata/yaml-fixtures/configs/global-config-default.yml:github-pat:4
testutil/test_constants.go:github-pat:363
testutil/test_constants.go:github-pat:455