Skip to content

Update developer-tool-faq.md - #196

Open
avgent wants to merge 1 commit into
IBM:masterfrom
avgent:inline-allowlisting
Open

avgent wants to merge 1 commit into
IBM:masterfrom
avgent:inline-allowlisting

Conversation

@avgent

@avgent avgent commented Sep 11, 2026

Copy link
Copy Markdown

Alexandre van Gent  [4:13 PM]
Hi Team,

https://github.com/IBM/detect-secrets/blob/master/docs/developer-tool-faq.md#how-do-i-use-inline-allowlisting
suggests that we can use use inline allowlisting
The tool supports the following inline allowlisting syntax.
Note: a space is needed between the original line content and the commentsecret # pragma: allowlist secretI tried that in a .md file as suggested by, originally,:bob-ibm:, but the the Gen2 pipeline failed on detect-secrets

I asked Bob:
Perhaps the documented pragma logic isn't working in .md files
and he said:
That's a very plausible explanation. The # pragma: allowlist secret comment syntax is designed for code files where # is a comment character. In a Markdown file, # inside a code block is just literal text — the detect-secrets scanner may not recognise it as a pragma directive there, so it gets ignored and the line is still flagged.
If that's the case:

The pragma approach works fine in.py,.sh,.yaml, etc.
It doesn't work in.mdfiles where the pragma sits inside a fenced code block
The baseline audit remains the only reliable fix specifically for Markdown files

IF that is true, can that be added to the faq ? (edited) 
7 repliesScott Moonen  [4:27 PM]
I think for Markdown you should be able to use either of these patterns:

secret
secret (edited)
Alexandre van Gent  [4:28 PM]
Thanks @smoonen will give it a try
[4:32 PM]But will that work also within a code block ? @smoonen
Scott Moonen  [4:33 PM]
Oh, interesting. My guess would be not.
Alexandre van Gent  [3:06 PM]
Can the faq be updated ? Or is a ticket required for that @smoonen
Scott Moonen  [9:21 PM]
You may be able to submit a PR to update it yourself, or perhaps file a bug in the repo
Alexandre van Gent  [9:23 PM]
Will do

Signed-off-by: Alexandre van Gent <A_VAN_GENT@fr.ibm.com>
@avgent
avgent force-pushed the inline-allowlisting branch from 3f3f5f5 to 519b100 Compare September 11, 2026 17:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant