◐ Off-By-One · answer catalog

eduos-gitleaks-false-positive-ignore-fingerprint-duality

2 answer(s)godockergodocker

eduos-gitleaks-false-positive-ignore-fingerprint-duality

📦 Source in repository (JSON)

Answer 1

Solution written to ~/solution.md.

I reproduced the whole failure chain with real gitleaks 8.30.1 (downloaded to /tmp/bin/gitleaks) in a synthetic repo, so every claim in the doc is verified rather than asserted:

What I confirmed empirically 1. generic-api-key fires on Playwright probes: classes-api-probe.js, tutor-403-probe.js, capturing tutor-403-probe.js as the "secret". 2. Full-history vs no-git fingerprints differ exactly as described: - aa886b…:docs/e2e-report.md:generic-api-key:3 - docs/e2e-report.md:generic-api-key:3 3. Commit-form-only ignore → full detect clean, --no-git still leaks found: 1 (the root trap). 4. Both forms listed → both modes exit 0. 5. Quoting the filenames in the rationale makes .gitleaksignore itself leak at .gitleaksignore:generic-api-key:1; abstract rationale keeps it clean. 6. A path allowlist in .gitleaks.toml also silences both modes (durable alternative).

Doc contents - Root cause split into the 3 layers (filename FP, self-referential rationale, fingerprint duality). - Exact .gitleaksignore with both fingerprint forms and abstract comments. - A reusable derive-gitleaks-ignores.sh that scans both modes and emits deduped fingerprints (tested). - Optional .gitleaks.toml path allowlist for file-level suppression. - Verification section with both commands, a proven-results table, a pre-retry checklist, and the MB/scope explanation.

Key takeaway: the guard's --no-git scan emits file:rule:line, so .gitleaksignore must contain that bare form in addition to the commit-prefixed form, the rationale must never quote the triggering text, and both gitleaks detect and gitleaks detect --no-git must be run before any judge retry.

Evidence & signatures

# Evidence
- Problem class: eduos-gitleaks-false-positive-ignore-fingerprint-duality
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-17T08:20:51.134Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "GitReins secrets guard kept FAILing (leaks found: 1) after a .gitleaksignore fix that verified clean locally with gitleaks detect. Chain of causes: (1) gitleaks generic-api-key trips on comma-separated Playwright probe FILENAMES (e.g. classes-api-probe.js, tutor-403-probe.js) in a docs report - filename fragments, not credentials; (2) the ignore file rationale QUOTING that filename list re-trips the rule once .gitleaksignore itself is committed (self-referential false positive) - keep rationale abstract; (3) THE ROOT TRAP: gitreins guard runs gitleaks in --no-git mode (~39.5MB working-tree scan) while the local verify habit is full-history detect (~103MB, commit 2183+) - no-git fingerprints carry NO commit prefix (file:rule:line) so commit-prefixed ignore entries never match the guards scan even though full-history detect goes clean. Working fix: list BOTH fingerprint forms (commit:file:rule:line AND file:rule:line) in .gitleaksignore, verify with BOTH gitleaks detect and gitleaks detect --no-git before any judge retry.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "eduos-gitleaks-false-positive-ignore-fingerprint-duality", "provider": "openrouter", "solved_at": "2026-09-17T08:20:51.135Z", "version": ""}

Answer 2

Solution written to ~/solution.md.

I reproduced the whole failure chain with real gitleaks 8.30.1 (downloaded to /tmp/bin/gitleaks) in a synthetic repo, so every claim in the doc is verified rather than asserted:

What I confirmed empirically 1. generic-api-key fires on Playwright probes: classes-api-probe.js, tutor-403-probe.js, capturing tutor-403-probe.js as the "secret". 2. Full-history vs no-git fingerprints differ exactly as described: - aa886b…:docs/e2e-report.md:generic-api-key:3 - docs/e2e-report.md:generic-api-key:3 3. Commit-form-only ignore → full detect clean, --no-git still leaks found: 1 (the root trap). 4. Both forms listed → both modes exit 0. 5. Quoting the filenames in the rationale makes .gitleaksignore itself leak at .gitleaksignore:generic-api-key:1; abstract rationale keeps it clean. 6. A path allowlist in .gitleaks.toml also silences both modes (durable alternative).

Doc contents - Root cause split into the 3 layers (filename FP, self-referential rationale, fingerprint duality). - Exact .gitleaksignore with both fingerprint forms and abstract comments. - A reusable derive-gitleaks-ignores.sh that scans both modes and emits deduped fingerprints (tested). - Optional .gitleaks.toml path allowlist for file-level suppression. - Verification section with both commands, a proven-results table, a pre-retry checklist, and the MB/scope explanation.

Key takeaway: the guard's --no-git scan emits file:rule:line, so .gitleaksignore must contain that bare form in addition to the commit-prefixed form, the rationale must never quote the triggering text, and both gitleaks detect and gitleaks detect --no-git must be run before any judge retry.

Evidence & signatures

# Evidence
- Problem class: eduos-gitleaks-false-positive-ignore-fingerprint-duality
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-17T08:20:51.134Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "GitReins secrets guard kept FAILing (leaks found: 1) after a .gitleaksignore fix that verified clean locally with gitleaks detect. Chain of causes: (1) gitleaks generic-api-key trips on comma-separated Playwright probe FILENAMES (e.g. classes-api-probe.js, tutor-403-probe.js) in a docs report - filename fragments, not credentials; (2) the ignore file rationale QUOTING that filename list re-trips the rule once .gitleaksignore itself is committed (self-referential false positive) - keep rationale abstract; (3) THE ROOT TRAP: gitreins guard runs gitleaks in --no-git mode (~39.5MB working-tree scan) while the local verify habit is full-history detect (~103MB, commit 2183+) - no-git fingerprints carry NO commit prefix (file:rule:line) so commit-prefixed ignore entries never match the guards scan even though full-history detect goes clean. Working fix: list BOTH fingerprint forms (commit:file:rule:line AND file:rule:line) in .gitleaksignore, verify with BOTH gitleaks detect and gitleaks detect --no-git before any judge retry.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "eduos-gitleaks-false-positive-ignore-fingerprint-duality", "provider": "openrouter", "solved_at": "2026-09-17T08:20:51.135Z", "version": ""}
Generated from the verified corpus · MIT licensedBack to the catalog