Files
claude/.gitleaks.toml
T

41 lines
1.9 KiB
TOML

title = "claude-config gitleaks config"
# Backstop scanner (job7): pre-commit hook (lib/gitflow.sh emit-hook) and
# `make scan-secrets`. Extends gitleaks' default ruleset — never replaces it.
[extend]
useDefault = true
# 3 false-positive classes identified in job7 triage (.audit/job7/ALL-REDACTED.json),
# each verified empirically against the real flagged files before being added
# here (see .audit/job7-report.md). None of these are live secrets.
[allowlist]
description = "job7 triage — known false positives, not secrets"
# Content-based: git-game repo test fixtures (#5/#6 in the triage), confirmed
# synthetic by the repo owner — literal "test-secret-<digits>" values used in
# unit tests, flagged by the generic-api-key rule on entropy alone.
regexTarget = "match"
regexes = [
'''test-secret-[0-9-]+''',
]
# Path-based: third-party/vendored files outside our control, flagged by
# rules that don't apply to their content.
paths = [
# Official claude-plugins marketplace catalog — 40-char hex "sha" (git
# commit references, not credentials) trip the sourcegraph-access-token
# rule, which matches on bare hex length/entropy alone.
'''plugins/marketplaces/.*marketplace\.json$''',
# superpowers plugin test fixture — a base64-encoded WS protocol test
# nonce, not a credential, trips generic-api-key on entropy.
'''tests/brainstorm-server/ws-protocol\.test\.js$''',
# NOT a job7 false positive — this IS a real secret, by design: the
# canonical vault (BDR-026). `make scan-secrets` scans ~/.claude looking
# for stray COPIES of secrets outside this file; flagging the vault
# itself on every run is pure noise, not signal.
'''(^|/)\.env$''',
# seo-data OAuth token store — legitimate local secret (like ~/.claude/.env),
# 0600, outside git. Allowlisted so `make scan-secrets` doesn't flag the vault.
'''(^|/)\.claude/seo-data/tokens\.json$''',
]