mirror of
https://github.com/larksuite/cli.git
synced 2026-09-14 18:42:53 +08:00
03781b2384
The example app id in the catalog is the public placeholder from the open platform documentation, not a credential. Its shape is what causes trouble: cli_ followed by exactly sixteen lowercase alphanumerics is what this repository's own lark-bot-app-id detector looks for, so gitleaks reports the four example values in im.json and task.json. On the branch those reports were suppressed by .gitleaksignore fingerprints, and a gitleaks fingerprint is bound to a commit SHA. Squash-merging #2232 moved the same content into a new commit, every fingerprint stopped matching, and the push scan on main reported all four. Two of them were never covered by a fingerprint at all; they stayed quiet only because the branch's incremental scans no longer reached the commit that introduced them. Shortening the placeholder to cli_example keeps the examples readable and takes them out of the detector's shape, so the reports go away at the source instead of being re-pinned to a SHA that the next squash would invalidate. The two fingerprints that named these task.json values are dropped with them. Verified with gitleaks v8.18.4 against this repository's own config: four reports on the merge commit before the change, none after, and none with the ignore file removed entirely. Manifest size and sha256 are recomputed for the two shards.