Conversation
Signed-off-by: Alexandre van Gent <A_VAN_GENT@fr.ibm.com>
avgent
force-pushed
the
inline-allowlisting
branch
from
September 11, 2026 17:21
3f3f5f5 to
519b100
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Alexandre van Gent [4:13 PM]
Hi Team,
https://github.com/IBM/detect-secrets/blob/master/docs/developer-tool-faq.md#how-do-i-use-inline-allowlisting
suggests that we can use use inline allowlisting
The tool supports the following inline allowlisting syntax.
Note: a space is needed between the original line content and the commentsecret # pragma: allowlist secretI tried that in a .md file as suggested by, originally,:bob-ibm:, but the the Gen2 pipeline failed on detect-secrets
I asked Bob:
Perhaps the documented pragma logic isn't working in .md files
and he said:
That's a very plausible explanation. The # pragma: allowlist secret comment syntax is designed for code files where # is a comment character. In a Markdown file, # inside a code block is just literal text — the detect-secrets scanner may not recognise it as a pragma directive there, so it gets ignored and the line is still flagged.
If that's the case:
The pragma approach works fine in.py,.sh,.yaml, etc.
It doesn't work in.mdfiles where the pragma sits inside a fenced code block
The baseline audit remains the only reliable fix specifically for Markdown files
IF that is true, can that be added to the faq ? (edited)
7 repliesScott Moonen [4:27 PM]
I think for Markdown you should be able to use either of these patterns:
secret
secret (edited)
Alexandre van Gent [4:28 PM]
Thanks @smoonen will give it a try
[4:32 PM]But will that work also within a code block ? @smoonen
Scott Moonen [4:33 PM]
Oh, interesting. My guess would be not.
Alexandre van Gent [3:06 PM]
Can the faq be updated ? Or is a ticket required for that @smoonen
Scott Moonen [9:21 PM]
You may be able to submit a PR to update it yourself, or perhaps file a bug in the repo
Alexandre van Gent [9:23 PM]
Will do