CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/secrets-baseline-manager

Builds and maintains a unified secrets baseline/allowlist across gitleaks (.gitleaksignore + --baseline-path), TruffleHog (--results=verified filter + trufflehog:ignore), and Kingfisher (--baseline-file + --exclude/--skip-* flags); adopts legacy findings without blocking PRs; enforces a waiver lifecycle (expires + approved_by + reason) stored in .secrets-waivers.yaml; prevents baseline rot via quarterly audit + expiry enforcement. Use when onboarding secrets scanning onto a repo that already has historical findings, or when per-scanner ignore configs have drifted out of sync and need consolidating into one governed allowlist.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

baseline-rot-prevention.mdreferences/

Preventing baseline rot

Deep reference for the secrets-baseline-manager skill - the three mechanisms that stop suppressed findings from accumulating over time with no review.

Quarterly audit script

Run at the start of each quarter (or automate in CI on a schedule):

#!/usr/bin/env bash
# audit-waivers.sh - flag expired or near-expiry waivers
TODAY=$(date +%Y-%m-%d)
WARN_DAYS=30

python3 - <<'EOF'
import yaml, sys
from datetime import date, timedelta

with open('.secrets-waivers.yaml') as f:
    waivers = yaml.safe_load(f).get('waivers', [])

today = date.today()
warn_cutoff = today + timedelta(days=30)
issues = []

for w in waivers:
    exp = date.fromisoformat(w.get('expires', '1970-01-01'))
    if exp < today:
        issues.append(f"EXPIRED   {w['id']} ({w['file']}) - expired {exp}")
    elif exp <= warn_cutoff:
        issues.append(f"NEAR-EXPIRY {w['id']} ({w['file']}) - expires {exp}")

if issues:
    for i in issues: print(i)
    sys.exit(1)
print(f"All {len(waivers)} waivers valid.")
EOF

Kingfisher stale-entry pruning

Per kf, running --manage-baseline automatically removes entries no longer present in the repo. Schedule this in CI after each merge to main:

kingfisher scan . --confidence low \
  --manage-baseline --baseline-file .secrets/kingfisher-baseline.yml
git diff --quiet .secrets/kingfisher-baseline.yml \
  || git commit -m "chore: prune stale kingfisher baseline entries"

Gitleaks baseline refresh cadence

Per gl, --baseline-path only filters findings that match the baseline JSON by fingerprint. Old baseline entries for rotated secrets do not cause false negatives - they simply have no effect. However, accumulated stale entries obscure the true size of accepted debt. Regenerate the baseline after each bulk rotation:

gitleaks git --report-format json \
  --report-path .secrets/gitleaks-baseline.json

Sources

  • gl - gitleaks: --baseline-path, .gitleaksignore, [[allowlists]].
  • kf - Kingfisher: --baseline-file, --manage-baseline.

SKILL.md

tile.json