Skip to content

GitGuardian: scanner test fixtures in test/scanner_suppression_test.exs red every PR (false positive, incident 37657201) #887

Description

@hyperpolymath

Finding

GitGuardian (app 46505) fails every PR that touches test/scanner_suppression_test.exs with Generic High Entropy Secret. It is one incident (37657201 in the GitGuardian workspace), re-reported on each PR: #867, #875, #878, #879, #883 as of 2026-09-30.

Verdict: false positive. The flagged strings are deliberate fixtures that test hypatia's own secret-detection suppression logic. Their shapes (values deliberately not reproduced here): a 16-character leetspeak password = "…" literal, an api_key: literal made of ghp_ followed by one repeated lowercase letter, and your-api-key / placeholder style values. None is a live credential.

The cost is real even though the finding is not: the red check is noise on every PR in this area, and it trains reviewers to ignore GitGuardian. That is how a true positive would slip through later.

Acceptance criteria

  • No committed literal in test/ matches a credential shape. Assemble fixture tokens at test runtime instead, for example "ghp_" <> String.duplicate("a", 36). Where a literal must stay, put a # ggignore comment on that line. Do not add a path-wide ignore for test/, because that would also hide a real leak in a test.
  • A PR touching test/scanner_suppression_test.exs gets a GitGuardian Security Checks: SUCCESS check-run.
  • The hypatia test suite still passes, and each fixture still exercises the detector it was written for. Prove it with a mutant: break the fixture, and the matching test must fail.
  • The owner resolves incident 37657201 in the GitGuardian dashboard as a test credential, which only the owner can do.

Census and method are in the session scratch. The search covered failing PRs in both orgs updated since 2026-09-16, and this repo accounts for 5 of the 6 GitGuardian failures found.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    testingTests, benchmarks, fuzzing, property checks, coverage

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions