Finding
GitGuardian (app 46505) fails every PR that touches test/scanner_suppression_test.exs with Generic High Entropy Secret. It is one incident (37657201 in the GitGuardian workspace), re-reported on each PR: #867, #875, #878, #879, #883 as of 2026-09-30.
Verdict: false positive. The flagged strings are deliberate fixtures that test hypatia's own secret-detection suppression logic. Their shapes (values deliberately not reproduced here): a 16-character leetspeak password = "…" literal, an api_key: literal made of ghp_ followed by one repeated lowercase letter, and your-api-key / placeholder style values. None is a live credential.
The cost is real even though the finding is not: the red check is noise on every PR in this area, and it trains reviewers to ignore GitGuardian. That is how a true positive would slip through later.
Acceptance criteria
Census and method are in the session scratch. The search covered failing PRs in both orgs updated since 2026-09-16, and this repo accounts for 5 of the 6 GitGuardian failures found.
🤖 Generated with Claude Code
https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
Finding
GitGuardian (app 46505) fails every PR that touches
test/scanner_suppression_test.exswith Generic High Entropy Secret. It is one incident (37657201 in the GitGuardian workspace), re-reported on each PR: #867, #875, #878, #879, #883 as of 2026-09-30.Verdict: false positive. The flagged strings are deliberate fixtures that test hypatia's own secret-detection suppression logic. Their shapes (values deliberately not reproduced here): a 16-character leetspeak
password = "…"literal, anapi_key:literal made ofghp_followed by one repeated lowercase letter, andyour-api-key/placeholderstyle values. None is a live credential.The cost is real even though the finding is not: the red check is noise on every PR in this area, and it trains reviewers to ignore GitGuardian. That is how a true positive would slip through later.
Acceptance criteria
test/matches a credential shape. Assemble fixture tokens at test runtime instead, for example"ghp_" <> String.duplicate("a", 36). Where a literal must stay, put a# ggignorecomment on that line. Do not add a path-wide ignore fortest/, because that would also hide a real leak in a test.test/scanner_suppression_test.exsgets a GitGuardian Security Checks: SUCCESS check-run.Census and method are in the session scratch. The search covered failing PRs in both orgs updated since 2026-09-16, and this repo accounts for 5 of the 6 GitGuardian failures found.
🤖 Generated with Claude Code
https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57