Skip to content
Benchmarks

redact-secret · Report · Detector

Pulumi access tokens

  • 26 fixtures
  • Format evidence: T1 · Provider-documented
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

  • Provider documentation pul- prefixed opaque token · observed 2026-09-21 · Pulumi's own Cloud REST API reference states, of the token-creation response: "The response includes the token ID and the tokenValue (prefixed with 'pul-')." Its personal-access-tokens sibling page carries the identical sentence. Neither page states a length or alphabet for the value that follows the prefix
  • trufflehog 3.97.4
  • gitleaks 8.30.1

Body length and alphabet are tool-corroborated, not provider-documented: gitleaks 8.30.1's pulumi-api-token rule and trufflehog 3.97.4's pulumi detector independently pin exactly 40 lowercase hexadecimal bytes after the prefix; neither registers any other length or alphabet, so this contract asserts none. Both tools pin the body to exactly 40 bytes rather than a floor, so a 39- or 41-byte body is an intentional false negative. github.com/plenoai/pleno-dlp, the second tool the product ADR cites for this family, is not one of this suite's pinned scanners and is recorded here only as prose, never as a pinned corroboration entry. All three token kinds (personal, organization, team) share this one prefix and body shape; Pulumi's own REST API reference documents no kind-specific prefix.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Pulumi access tokens fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated11False alarmsat most 25.9%0 of 11 controls flagged11 quiet · 0 flagged
  • flare-redact at most 25.9%
  • gitleaks at most 25.9%
  • trufflehog at most 37.7%
Must not flag · Project policy3False alarmsinsufficient-evidence0 of 3 controls flagged3 quiet · 0 flagged
  • flare-redact insufficient-evidence
  • gitleaks insufficient-evidence
  • trufflehog insufficient-evidence
Must redact · Provider-documented12Secret spans left readableat most 24.3%0 of 12 spansNear-twins told apartat least 61.0%6 of 6 pairs12 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 100.0%
  • gitleaks at most 24.3%
  • trufflehog at most 24.3%
26 of 26 rows
Fixtures
26
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

26 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Pulumi access tokens
FixtureKind and evidenceredact-secret
pulumi-access-token-env-access-tokenpulumi · documented-format-literalMust redactT1 · Provider-documentedRedacted
pulumi-access-token-github-actions-previewpulumi · documented-format-literalMust redactT1 · Provider-documentedRedacted
pulumi-access-token-invalid-alphabetpulumi · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
pulumi-access-token-organization-shape-barepulumi · documented-format-literalMust redactT1 · Provider-documentedRedacted
pulumi-access-token-organization-shape-quotedpulumi · documented-format-literalMust redactT1 · Provider-documentedRedacted
pulumi-access-token-organization-shape-unicode-crlfpulumi · documented-format-literalMust redactT1 · Provider-documentedRedacted
pulumi-access-token-personal-shape-barepulumi · documented-format-literalMust redactT1 · Provider-documentedRedacted
pulumi-access-token-personal-shape-quotedpulumi · documented-format-literalMust redactT1 · Provider-documentedRedacted
pulumi-access-token-personal-shape-unicode-crlfpulumi · documented-format-literalMust redactT1 · Provider-documentedRedacted
pulumi-access-token-rest-api-token-headerpulumi · documented-format-literalMust redactT1 · Provider-documentedRedacted
pulumi-access-token-team-shape-barepulumi · documented-format-literalMust redactT1 · Provider-documentedRedacted
pulumi-access-token-team-shape-quotedpulumi · documented-format-literalMust redactT1 · Provider-documentedRedacted
pulumi-access-token-team-shape-unicode-crlfpulumi · documented-format-literalMust redactT1 · Provider-documentedRedacted
pulumi-access-token-maskpulumi · benign-lookalikeMust not flagT3 · Project policyQuiet
pulumi-access-token-organization-shape-bare-twinpulumi · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
pulumi-access-token-organization-shape-quoted-twinpulumi · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
pulumi-access-token-organization-shape-unicode-crlf-twinpulumi · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
pulumi-access-token-personal-shape-bare-twinpulumi · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
pulumi-access-token-personal-shape-quoted-twinpulumi · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
pulumi-access-token-personal-shape-unicode-crlf-twinpulumi · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
pulumi-access-token-prefix-onlypulumi · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
pulumi-access-token-referencepulumi · benign-lookalikeMust not flagT3 · Project policyQuiet
pulumi-access-token-short-bodypulumi · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
pulumi-access-token-token-create-response-id-public-idpulumi · public-identifierMust not flagT2 · Tool-corroboratedQuiet
pulumi-access-token-token-kinds-note-prosepulumi · prose-mentionMust not flagT3 · Project policyQuiet
pulumi-access-token-trailing-identifier-embeddingpulumi · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet