diff --git a/trufflehog/exclude-paths.txt b/trufflehog/exclude-paths.txt index ca188f8e..0d935cb4 100644 --- a/trufflehog/exclude-paths.txt +++ b/trufflehog/exclude-paths.txt @@ -29,3 +29,7 @@ grafana\.json$ # Grafana dashboards (user-supplied site content, full of base64/hashes) content/grafana/dashboards + +# Yarn 4 release bundle (corepack-vendored, minified — fires false positives +# on `npmPublishProvenance` near internal mentions of GitLab; not user code) +\.yarn/releases/