Skip to content

fix(scripts): git-secrets GCP API-key pattern is an invalid bracket range, every scan exits 128 #327

Description

@cristim

scripts/setup-git-secrets.sh registers the GCP API-key detector as:

AIza[0-9A-Za-z-_]{35}

Inside a bracket expression a hyphen between two characters is a range, so Z-_ asks for the range from Z (0x5A) to _ (0x5F). That is a valid range, but 9A-Za-z-_ parses as 9, A-Z, a-z, -, _ only under some engines; BSD regex (Apple git), glibc regex (git 2.43 on Ubuntu 24.04) and GNU grep 3.12 all reject the expression with invalid character range.

git-secrets joins every registered pattern into a single git grep -E invocation, so one invalid pattern breaks every scan on that clone, not just this detector. Once registered, git secrets --scan exits 128, including from the pre-commit hook.

Present since the script was added in c7d3c8c49 (2026-02-20).

Fix

Put the hyphen last so it is literal:

AIza[0-9A-Za-z_-]{35}

Why it has gone unnoticed

The script aborts earlier, at its PEM pattern, which git secrets --add rejects because it starts with a dash. With set -e the script never reaches the rest of its body, so on most machines the invalid pattern was never registered either. Anyone who patched past the abort would hit this immediately.

Found while measuring for LeanerCloud/cloud-commitments-cli#1972, which fixes it as its first commit since nothing else in that PR can be verified until scans run.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions