eduos-gitleaks-false-positive-ignore-fingerprint-duality
Solution written to ~/solution.md.
I reproduced the whole failure chain with real gitleaks 8.30.1 (downloaded to /tmp/bin/gitleaks) in a synthetic repo, so every claim in the doc is verified rather than asserted:
What I confirmed empirically
1. generic-api-key fires on Playwright probes: classes-api-probe.js, tutor-403-probe.js, capturing tutor-403-probe.js as the "secret".
2. Full-history vs no-git fingerprints differ exactly as described:
- aa886b…:docs/e2e-report.md:generic-api-key:3
- docs/e2e-report.md:generic-api-key:3
3. Commit-form-only ignore → full detect clean, --no-git still leaks found: 1 (the root trap).
4. Both forms listed → both modes exit 0.
5. Quoting the filenames in the rationale makes .gitleaksignore itself leak at .gitleaksignore:generic-api-key:1; abstract rationale keeps it clean.
6. A path allowlist in .gitleaks.toml also silences both modes (durable alternative).
Doc contents
- Root cause split into the 3 layers (filename FP, self-referential rationale, fingerprint duality).
- Exact .gitleaksignore with both fingerprint forms and abstract comments.
- A reusable derive-gitleaks-ignores.sh that scans both modes and emits deduped fingerprints (tested).
- Optional .gitleaks.toml path allowlist for file-level suppression.
- Verification section with both commands, a proven-results table, a pre-retry checklist, and the MB/scope explanation.
Key takeaway: the guard's --no-git scan emits file:rule:line, so .gitleaksignore must contain that bare form in addition to the commit-prefixed form, the rationale must never quote the triggering text, and both gitleaks detect and gitleaks detect --no-git must be run before any judge retry.
# Evidence - Problem class: eduos-gitleaks-false-positive-ignore-fingerprint-duality - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-17T08:20:51.134Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "GitReins secrets guard kept FAILing (leaks found: 1) after a .gitleaksignore fix that verified clean locally with gitleaks detect. Chain of causes: (1) gitleaks generic-api-key trips on comma-separated Playwright probe FILENAMES (e.g. classes-api-probe.js, tutor-403-probe.js) in a docs report - filename fragments, not credentials; (2) the ignore file rationale QUOTING that filename list re-trips the rule once .gitleaksignore itself is committed (self-referential false positive) - keep rationale abstract; (3) THE ROOT TRAP: gitreins guard runs gitleaks in --no-git mode (~39.5MB working-tree scan) while the local verify habit is full-history detect (~103MB, commit 2183+) - no-git fingerprints carry NO commit prefix (file:rule:line) so commit-prefixed ignore entries never match the guards scan even though full-history detect goes clean. Working fix: list BOTH fingerprint forms (commit:file:rule:line AND file:rule:line) in .gitleaksignore, verify with BOTH gitleaks detect and gitleaks detect --no-git before any judge retry.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "eduos-gitleaks-false-positive-ignore-fingerprint-duality", "provider": "openrouter", "solved_at": "2026-09-17T08:20:51.135Z", "version": ""}Solution written to ~/solution.md.
I reproduced the whole failure chain with real gitleaks 8.30.1 (downloaded to /tmp/bin/gitleaks) in a synthetic repo, so every claim in the doc is verified rather than asserted:
What I confirmed empirically
1. generic-api-key fires on Playwright probes: classes-api-probe.js, tutor-403-probe.js, capturing tutor-403-probe.js as the "secret".
2. Full-history vs no-git fingerprints differ exactly as described:
- aa886b…:docs/e2e-report.md:generic-api-key:3
- docs/e2e-report.md:generic-api-key:3
3. Commit-form-only ignore → full detect clean, --no-git still leaks found: 1 (the root trap).
4. Both forms listed → both modes exit 0.
5. Quoting the filenames in the rationale makes .gitleaksignore itself leak at .gitleaksignore:generic-api-key:1; abstract rationale keeps it clean.
6. A path allowlist in .gitleaks.toml also silences both modes (durable alternative).
Doc contents
- Root cause split into the 3 layers (filename FP, self-referential rationale, fingerprint duality).
- Exact .gitleaksignore with both fingerprint forms and abstract comments.
- A reusable derive-gitleaks-ignores.sh that scans both modes and emits deduped fingerprints (tested).
- Optional .gitleaks.toml path allowlist for file-level suppression.
- Verification section with both commands, a proven-results table, a pre-retry checklist, and the MB/scope explanation.
Key takeaway: the guard's --no-git scan emits file:rule:line, so .gitleaksignore must contain that bare form in addition to the commit-prefixed form, the rationale must never quote the triggering text, and both gitleaks detect and gitleaks detect --no-git must be run before any judge retry.
# Evidence - Problem class: eduos-gitleaks-false-positive-ignore-fingerprint-duality - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-17T08:20:51.134Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "GitReins secrets guard kept FAILing (leaks found: 1) after a .gitleaksignore fix that verified clean locally with gitleaks detect. Chain of causes: (1) gitleaks generic-api-key trips on comma-separated Playwright probe FILENAMES (e.g. classes-api-probe.js, tutor-403-probe.js) in a docs report - filename fragments, not credentials; (2) the ignore file rationale QUOTING that filename list re-trips the rule once .gitleaksignore itself is committed (self-referential false positive) - keep rationale abstract; (3) THE ROOT TRAP: gitreins guard runs gitleaks in --no-git mode (~39.5MB working-tree scan) while the local verify habit is full-history detect (~103MB, commit 2183+) - no-git fingerprints carry NO commit prefix (file:rule:line) so commit-prefixed ignore entries never match the guards scan even though full-history detect goes clean. Working fix: list BOTH fingerprint forms (commit:file:rule:line AND file:rule:line) in .gitleaksignore, verify with BOTH gitleaks detect and gitleaks detect --no-git before any judge retry.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "eduos-gitleaks-false-positive-ignore-fingerprint-duality", "provider": "openrouter", "solved_at": "2026-09-17T08:20:51.135Z", "version": ""}