Use inline trufflehog:ignore instead of exclude paths file

Inline comments are more targeted than excluding the entire file
from secret scanning. Remove the .trufflehog.yml exclude file and
the --exclude-paths flag from the workflow.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
Bryan Frimin
2026-03-27 12:42:03 +01:00
committed by Sacha Al Himdani
parent bba7855678
commit 7dcc3d21ac
3 changed files with 5 additions and 6 deletions

View File

@@ -82,12 +82,12 @@ func TestSensitiveDataGuardrail_Check(t *testing.T) {
{"pem certificate", "-----BEGIN CERTIFICATE-----\nMIIE...", true},
// Connection strings
{"postgres uri", "Connect to postgres://user:pass@host/db", true},
{"postgresql uri", "Connect to postgresql://user:pass@host/db", true},
{"mongodb uri", "Use mongodb://user:pass@host/db", true},
{"postgres uri", "Connect to postgres://user:pass@host/db", true}, // trufflehog:ignore
{"postgresql uri", "Connect to postgresql://user:pass@host/db", true}, // trufflehog:ignore
{"mongodb uri", "Use mongodb://user:pass@host/db", true}, // trufflehog:ignore
{"mysql uri", "Use mysql://user:pass@host/db", true},
{"redis uri", "Cache at redis://localhost:6379", true},
{"amqp uri", "Queue at amqp://guest:guest@host/vhost", true},
{"amqp uri", "Queue at amqp://guest:guest@host/vhost", true}, // trufflehog:ignore
// Generic secret field names
{"encryption_key", "The encryption_key is set in config", true},