chore(audit): untrack gitleaks reports; allowlist triaged FP classes

Reports are gitignored (.gitignore:94) but were swept into 17bdd08 —
even redacted they map secret types/locations for anyone with repo
access. Allowlists from the 2026-07-14 cso triage (75 findings → 0,
each class verified empirically): bare 40-hex git SHAs, gitflow-test
synthetic AWS fixture, presigned-URL key ids, expired GitHub image
JWTs, doc placeholders, IDE lock files, two prose literals. Converted
deprecated [allowlist] to [[allowlists]] (gitleaks 8.30 refuses the
mix). Makefile hint no longer suggests committing the reports.
Transcripts/file-history deliberately NOT path-allowlisted (BDR-057).
This commit is contained in:
Bastien Chanot
2026-07-14 18:07:11 +02:00
parent b7106761b0
commit 20b90465d8
4 changed files with 48 additions and 311 deletions
+1 -1
View File
@@ -48,7 +48,7 @@ scan-secrets: ## Gitleaks sweep: this repo's history + ~/.claude (job7 backstop)
echo "== $$r (git history) =="; \
gitleaks git "$$r" -c .gitleaks.toml --no-banner --redact -f json -r ".audit/scan-secrets-$$(basename "$$r").json" || fail=1; \
done; \
echo "Reports: .audit/scan-secrets-*.json (already redacted — safe to inspect/commit)"; \
echo "Reports: .audit/scan-secrets-*.json (redacted; gitignored — keep local, do NOT commit)"; \
exit $$fail
profile: ## Run profile.sh (usage: make profile cmd="set design")