You can reduce false positives from deliberate test credentials by excluding a narrowly defined fixture path or, when supported, by combining that path with a test-value condition. But an exclusion can also hide a real credential in the excluded location. Configure the scanner and scan mode you actually use, then validate the exception with a non-live test value and review it as code.
First, understand what an exclusion hides
Path-based exclusions are not a way to tell whether a value is fake. They change what the scanner reports for a location. GitHub says alerts for secrets in excluded paths are automatically closed and those directories are excluded from push protection. GitLab’s documented source-code allowlist example ignores a finding when its path matches. As a result, a real credential committed under an excluded fixture path may be suppressed along with deliberate test data. This is an inference from the documented behavior, not a guarantee that every scanner handles exclusions identically.
Where the scanner supports it, a narrower exception can require both a fixture path and a known test-value pattern to match. That reduces the chance that an unrelated value in the directory is ignored, but only if the scanner’s logic is actually AND. Confirm the product, scan mode, release, and matching semantics before relying on an exception.
Choose the configuration for your scanner
| Scanner and mode | Configuration | Scope and matching behavior | Important caveat |
|---|---|---|---|
| GitHub Secret Scanning | .github/secret_scanning.yml using paths-ignore |
Closes alerts for secrets in matching paths and excludes those directories from push protection. | Only the first 1,000 entries are excluded when the list exceeds 1,000; a file larger than 1 MB is ignored. GitHub Docs |
| GitLab Secret Scanning for Source Code | .gitlab/secret-detection-ruleset.toml, with an extended configuration when needed |
The documented allowlist example combines paths and regexes using OR, so either a matching path or matching regex can ignore a finding. |
Do not assume that adding a regex makes a path exclusion narrower. Verify the effective ruleset for the deployed scanner. GitLab Docs |
| Gitleaks | Allowlist under a specific rule or a global [[allowlists]] entry |
Supports path, regex, commit, and stopword criteria; condition settings determine whether any or all criteria must match. A global allowlist can affect findings across rules. | In v8.25.0, [allowlist] was replaced by [[allowlists]]. Match configuration syntax to the installed release. Gitleaks documentation |
Configure a narrow exception
GitHub Secret Scanning
Create or edit .github/secret_scanning.yml and add the smallest stable path that contains deliberate test data only. For example, if your repository keeps these files in tests/fixtures/secrets/, the configuration could be:
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
paths-ignore:
- "tests/fixtures/secrets/**"
Replace the example with your repository’s actual fixture path; do not use a broad directory simply because it is convenient. GitHub supports * in patterns. Its documentation recommends limiting excluded directories, explaining their purpose in comments, reviewing the configuration regularly, and informing the security team.
GitHub’s documentation also describes a way to verify an exclusion: use a pre-invalidated or test secret in an excluded file and check whether an alert opens. Use only a non-live test value; never put an active credential into a test to see whether scanning catches it.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
GitLab Secret Scanning for Source Code
GitLab supports customization through .gitlab/secret-detection-ruleset.toml, including extending its packaged ruleset and referencing an extended configuration file. Its documented example uses an [[allowlists]] entry with path and regular-expression criteria. Because those lists are combined with OR, a matching path alone can ignore a finding. Adding a regex to that example does not necessarily require both conditions.
The example path spec/fixtures/.* and its sample regex illustrate syntax; they are not a safe policy to copy unchanged. Check the effective ruleset and matching behavior for the version you deploy. GitLab’s source-code scanner configuration is distinct from pipeline secret detection, so confirm which mechanism is running.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Gitleaks
Gitleaks allowlists can be attached to individual rules or defined globally. If a fixture exception should affect only a particular detector, prefer the narrow rule-level scope over a global exception that could skip findings across rules. Its documented criteria include paths and regular expressions, and its condition settings control whether criteria are joined with AND or OR.
For a fixture exception intended to match both a directory and a known test-value pattern, use AND only if the installed Gitleaks configuration supports and applies that condition to the intended fields. Confirm the exact fields and regex target for the installed release, and use the syntax appropriate to that version: the project documents the transition from [allowlist] to [[allowlists]] in v8.25.0.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Roll out and maintain the exception safely
- Separate test data. Put deliberately fake credentials in a dedicated fixture directory rather than mixing them with application code or production configuration. This makes a narrow path exception easier to define and review.
- Exclude the smallest stable scope. Prefer an exact fixture path or a narrow subtree over a broad test, documentation, or configuration directory. Where supported, use a path plus a known test-value condition with verified AND semantics.
- Explain the exception in the configuration. Add a comment stating why the path or rule is excluded, and include the change in ordinary code review. GitHub specifically recommends documenting exclusions and communicating them to the security team.
- Validate with a non-live value. Test the configuration in a controlled repository or fixture and confirm the expected alert behavior. Never use a valid credential for this check.
- Revisit it when the repository or scanner changes. Review exclusions when fixture layouts, scanner versions, or scan modes change; a path that once held only test data may not remain isolated.
- Handle history separately. Removing a value from the current working tree does not necessarily remove it from Git history. GitLab warns that pipeline secret detection can still report secrets retained in repository history. Treat any real credential as exposed and follow your organization’s rotation and incident-response process; an ignore rule is not remediation. GitLab Docs
Check what your setting affects
Before merging an exclusion, establish whether it changes an alert, a particular detector rule, or scanning of an entire path; whether criteria combine with AND or OR; and whether it affects push protection or pipeline findings. These are product- and mode-specific behaviors, not interchangeable settings. GitHub documents alert and push-protection effects, while GitLab distinguishes source-code scanning from pipeline secret detection; Gitleaks documents rule-level and global allowlists.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

