scripts/setup-git-secrets.sh registers three connection-string detectors whose shape is roughly scheme://[^@]+@.
git-secrets scans with git grep -nwHEI, and -w requires the match to end on a word boundary. [^@]+@ always ends at the @, and the next character is the first letter of the hostname, which is a word character. There is no boundary there, so the match is rejected.
Measured: a staged file containing a realistic connection string with an embedded password scans clean (exit 0). Only format strings fire, because they end in a placeholder rather than a hostname letter.
So these detectors match placeholder text and miss the actual thing they exist to catch.
Fix shape
Consume the host so the match ends on a boundary:
Worth re-measuring the whole tree after changing it, since consuming the host widens what the pattern can hit.
Found while measuring for LeanerCloud/cloud-commitments-cli#1972. Deliberately not fixed there to keep that PR's blast radius to the allowlist.
scripts/setup-git-secrets.shregisters three connection-string detectors whose shape is roughlyscheme://[^@]+@.git-secrets scans with
git grep -nwHEI, and-wrequires the match to end on a word boundary.[^@]+@always ends at the@, and the next character is the first letter of the hostname, which is a word character. There is no boundary there, so the match is rejected.Measured: a staged file containing a realistic connection string with an embedded password scans clean (exit 0). Only format strings fire, because they end in a placeholder rather than a hostname letter.
So these detectors match placeholder text and miss the actual thing they exist to catch.
Fix shape
Consume the host so the match ends on a boundary:
Worth re-measuring the whole tree after changing it, since consuming the host widens what the pattern can hit.
Found while measuring for LeanerCloud/cloud-commitments-cli#1972. Deliberately not fixed there to keep that PR's blast radius to the allowlist.