Skip to content

ci(gitleaks): baseline allowlist#794

Draft
KooshaPari wants to merge 1 commit into
mainfrom
fix/agileplus-gitleaks
Draft

ci(gitleaks): baseline allowlist#794
KooshaPari wants to merge 1 commit into
mainfrom
fix/agileplus-gitleaks

Conversation

@KooshaPari

@KooshaPari KooshaPari commented Jun 23, 2026

Copy link
Copy Markdown
Owner

Summary

Adds .gitleaks.toml baseline allowlist to prevent false positives on secret scanning.

Stack Topology

  • Head branch: fix/agileplus-gitleaks
  • Base branch: main
  • Lane: automated composer/forge lane (layered-pr-exception)
  • Kitty-spec: kitty-specs/eco-045-gitleaks-baseline/

spec: eco-045-gitleaks-baseline

Validation

  • Governance template sections present (Summary, Stack Topology, Validation, Governance, CI Exception)
  • Kitty-spec registered on main via governance compliance PR (eco-035..047)
  • Local tests (deferred to lane author; no billed CI per policy)
  • Rebase on main after governance compliance merge for spec-first directory presence

Governance

  • Conventional Commit PR title (lowercase subject)
  • spec: eco-045-gitleaks-baseline traceability line
  • layered-pr-exception label for direct-to-main automated lanes
  • policy-gate / pr-governance-gate / spec-first alignment (metadata-only; gates not weakened)

CI Exception

layered-pr-exception: automated lane targets main directly per stack rollout policy. No ci-billing-exception. Rebase on main after kitty-spec registration lands to satisfy spec-first on branch head.

@gemini-code-assist

Copy link
Copy Markdown

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@github-actions

Copy link
Copy Markdown

🔍 Legacy Tooling Anti-Pattern Scan

Repository: KooshaPari/AgilePlus
Total Violations: 0

  • 🔴 Critical: 0
  • 🟠 High: 0
  • 🟡 Medium: 0
  • 🔵 Low: 0

✅ No legacy tooling anti-patterns detected!

📄 View Full Report

@github-actions

Copy link
Copy Markdown

Snyk Security Scan Results

Snyk vulnerability scan completed. View results in GitHub Code Scanning dashboard.

@KooshaPari KooshaPari added the layered-pr-exception Exception to allow fix/* branches to target main directly label Jun 25, 2026
@KooshaPari KooshaPari closed this Jun 25, 2026
@KooshaPari KooshaPari reopened this Jun 25, 2026
@sonarqubecloud

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown

🔍 Legacy Tooling Anti-Pattern Scan

Repository: KooshaPari/AgilePlus
Total Violations: 0

  • 🔴 Critical: 0
  • 🟠 High: 0
  • 🟡 Medium: 0
  • 🔵 Low: 0

✅ No legacy tooling anti-patterns detected!

📄 View Full Report

@github-actions

Copy link
Copy Markdown

Snyk Security Scan Results

Snyk vulnerability scan completed. View results in GitHub Code Scanning dashboard.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

layered-pr-exception Exception to allow fix/* branches to target main directly

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant