From 5237e57d27b1e37210ff7fc8caaccad34f18b250 Mon Sep 17 00:00:00 2001 From: Bryan Frimin Date: Fri, 27 Mar 2026 12:46:03 +0100 Subject: [PATCH] Revert "Use inline trufflehog:ignore instead of exclude paths file" This reverts commit f10ecb8210b1176311d9372d1108b91ce8290fd4. Signed-off-by: Bryan Frimin --- .github/workflows/secrets.yaml | 2 +- .trufflehog.yml | 1 + pkg/agent/guardrail/sensitive_data_test.go | 8 ++++---- 3 files changed, 6 insertions(+), 5 deletions(-) create mode 100644 .trufflehog.yml diff --git a/.github/workflows/secrets.yaml b/.github/workflows/secrets.yaml index 4119da879..c0c8d0836 100644 --- a/.github/workflows/secrets.yaml +++ b/.github/workflows/secrets.yaml @@ -19,4 +19,4 @@ jobs: submodules: recursive - uses: "trufflesecurity/trufflehog@b78fbfd8eb982f4802e09a265fb2bc37b3040975" # main with: - extra_args: "--results=verified,unknown" + extra_args: "--results=verified,unknown --exclude-paths=.trufflehog.yml" diff --git a/.trufflehog.yml b/.trufflehog.yml new file mode 100644 index 000000000..58f3205bb --- /dev/null +++ b/.trufflehog.yml @@ -0,0 +1 @@ +pkg/agent/guardrail/sensitive_data_test\.go diff --git a/pkg/agent/guardrail/sensitive_data_test.go b/pkg/agent/guardrail/sensitive_data_test.go index f80add522..fdcd4a31a 100644 --- a/pkg/agent/guardrail/sensitive_data_test.go +++ b/pkg/agent/guardrail/sensitive_data_test.go @@ -82,12 +82,12 @@ func TestSensitiveDataGuardrail_Check(t *testing.T) { {"pem certificate", "-----BEGIN CERTIFICATE-----\nMIIE...", true}, // Connection strings - {"postgres uri", "Connect to postgres://user:pass@host/db", true}, // trufflehog:ignore - {"postgresql uri", "Connect to postgresql://user:pass@host/db", true}, // trufflehog:ignore - {"mongodb uri", "Use mongodb://user:pass@host/db", true}, // trufflehog:ignore + {"postgres uri", "Connect to postgres://user:pass@host/db", true}, + {"postgresql uri", "Connect to postgresql://user:pass@host/db", true}, + {"mongodb uri", "Use mongodb://user:pass@host/db", true}, {"mysql uri", "Use mysql://user:pass@host/db", true}, {"redis uri", "Cache at redis://localhost:6379", true}, - {"amqp uri", "Queue at amqp://guest:guest@host/vhost", true}, // trufflehog:ignore + {"amqp uri", "Queue at amqp://guest:guest@host/vhost", true}, // Generic secret field names {"encryption_key", "The encryption_key is set in config", true},