gitreins-judge-tier1-scans-retired-parquet-mirrors
Solution written to ~/solution.md and verified end-to-end against a local reproduction with the same layout.
Root cause — the tier1 secrets scan is a builtin full-tree regex scanner: it walks the entire working tree (tracked + untracked + gitignored), matches raw bytes, and never reads .gitleaks.toml. So (a) the allowlist was inert for the judge, (b) the retired gitignored mirrors .coding-hermes/board/tasks.parquet and board.db embedded the flagged row text, and (c) the allowlist file itself self-flagged because it contains the literal key. Separately, max_input_tokens: 200000 truncated tier2 runs needing ~215k → INCOMPLETE.
Fix (4 parts):
1. Sanitize board/tasks.jsonl: replace sk-a*** → REDACTED_FAKE_KEY (no sk- prefix, so no sk-… regex can match); construct runtime fakes instead of storing literals.
2. Delete retired parquet mirrors: git rm if tracked, rm -f if untracked — JSONL is canonical, no regeneration.
3. Sanitize board.db (duckdb) with UPDATE … replace(row_text, …) using the same placeholder (or regenerate from JSONL).
4. Bump max_input_tokens: 200000 → 1048576 (1M).
Verification (reproduced locally, judge-equivalent scanner):
- Scanner went from total_findings=5 (jsonl, parquet, board.db, .gitleaks.toml, fixture) to total_findings=0, exit 0
- grep -rl for the literal across the tree (incl. untracked+gitignored): NONE
- duckdb/sqlite row count for the key: 0; cache matches JSONL placeholder
- Non-literal allowlist regex still matches the dummy key for real gitleaks (True)
- config.yml parses with max_input_tokens = 1048576 (PyYAML 6.0.3)
One finding worth calling out: keep .gitleaks.toml but express the allowlist non-literally (e.g. sk-[a]1b2c3d4e5f6g7h8i9j0) — otherwise the literal inside the allowlist file is itself flagged by the full-tree scan.
# Evidence - Problem class: gitreins-judge-tier1-scans-retired-parquet-mirrors - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-17T23:42:44.704Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "The gitreins judge tier1 secrets scan runs a builtin full-tree regex scanner over the working tree including UNTRACKED gitignored non-dotdir files. On deepseek-dashboard the literal dummy key sk-a*** in a test fixture was allowlisted via .gitleaks.toml but the judge ignored the allowlist; after replacing the fixtures the scan still flagged .coding-hermes/board/tasks.parquet (a retired gitignored parquet mirror that embeds board row text) and would have flagged board.db. Fix: git rm the retired parquet mirrors (JSONL-canonical boards), regenerate or sanitize the duckdb board.db cache, and raise max_input_tokens 0.2M to 1M because tier2 INCOMPLETEs at 215k used.", "environment": "deepseek-dashboard repo, gitreins judge tier1", "language": "yaml", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "gitreins-judge-tier1-scans-retired-parquet-mirrors", "provider": "openrouter", "solved_at": "2026-08-17T23:42:44.704Z", "version": "gitreins 2026-08-17"}Solution written to ~/solution.md and verified end-to-end against a local reproduction with the same layout.
Root cause — the tier1 secrets scan is a builtin full-tree regex scanner: it walks the entire working tree (tracked + untracked + gitignored), matches raw bytes, and never reads .gitleaks.toml. So (a) the allowlist was inert for the judge, (b) the retired gitignored mirrors .coding-hermes/board/tasks.parquet and board.db embedded the flagged row text, and (c) the allowlist file itself self-flagged because it contains the literal key. Separately, max_input_tokens: 200000 truncated tier2 runs needing ~215k → INCOMPLETE.
Fix (4 parts):
1. Sanitize board/tasks.jsonl: replace sk-a*** → REDACTED_FAKE_KEY (no sk- prefix, so no sk-… regex can match); construct runtime fakes instead of storing literals.
2. Delete retired parquet mirrors: git rm if tracked, rm -f if untracked — JSONL is canonical, no regeneration.
3. Sanitize board.db (duckdb) with UPDATE … replace(row_text, …) using the same placeholder (or regenerate from JSONL).
4. Bump max_input_tokens: 200000 → 1048576 (1M).
Verification (reproduced locally, judge-equivalent scanner):
- Scanner went from total_findings=5 (jsonl, parquet, board.db, .gitleaks.toml, fixture) to total_findings=0, exit 0
- grep -rl for the literal across the tree (incl. untracked+gitignored): NONE
- duckdb/sqlite row count for the key: 0; cache matches JSONL placeholder
- Non-literal allowlist regex still matches the dummy key for real gitleaks (True)
- config.yml parses with max_input_tokens = 1048576 (PyYAML 6.0.3)
One finding worth calling out: keep .gitleaks.toml but express the allowlist non-literally (e.g. sk-[a]1b2c3d4e5f6g7h8i9j0) — otherwise the literal inside the allowlist file is itself flagged by the full-tree scan.
# Evidence - Problem class: gitreins-judge-tier1-scans-retired-parquet-mirrors - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-17T23:42:44.704Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "The gitreins judge tier1 secrets scan runs a builtin full-tree regex scanner over the working tree including UNTRACKED gitignored non-dotdir files. On deepseek-dashboard the literal dummy key sk-a*** in a test fixture was allowlisted via .gitleaks.toml but the judge ignored the allowlist; after replacing the fixtures the scan still flagged .coding-hermes/board/tasks.parquet (a retired gitignored parquet mirror that embeds board row text) and would have flagged board.db. Fix: git rm the retired parquet mirrors (JSONL-canonical boards), regenerate or sanitize the duckdb board.db cache, and raise max_input_tokens 0.2M to 1M because tier2 INCOMPLETEs at 215k used.", "environment": "deepseek-dashboard repo, gitreins judge tier1", "language": "yaml", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "gitreins-judge-tier1-scans-retired-parquet-mirrors", "provider": "openrouter", "solved_at": "2026-08-17T23:42:44.704Z", "version": "gitreins 2026-08-17"}