Upstream supersedes `@21st-dev/magic` with `@21st-dev/cli` (bin `21st`): same endpoint, `21st login` in place of an API key, no MCP process loaded into every session. - install-plugins.sh Step 8.7: `npm i -g @21st-dev/cli` (pinned in plugins.lock.json), staged `21st skills install`, TTY-only login offer, pack disabled by default. update-all.sh 7.4 refreshes both. - The documented `21st install-skill` cannot be used: the installer refuses to follow a symlink on the target path and `~/.claude/skills` is one. The install runs under a throwaway HOME and the result moves into skills-external/21st-* (gitignored), symlinked on demand. - toggle-external.sh manages `21st` as a pack (names globbed from skills-external/21st-*, parked under plain names). `magic` is gone. - The 5 design skills join design/web/web-full/full and MANAGED_EXTERNALS; 21st-registry and 21st-design-sync stay parked. MANAGED_MCPS is now empty and profile.sh's dead magic branches are removed. - Design gate: GATE-BLOCK gains `21st` (required-manual, magic's old slot) and `21st-ui-build`; PATH repair extended to the npm global bin. - settings.json: the 4 mcp__magic__* ask entries go; the outward-facing 21st verbs land in autoMode.soft_deny, the tier that holds under auto mode (LRN-153). - Docs: README, CLAUDE.global.md, design-gate.md, profile SKILL.md, .env.example, .gitleaks.toml, link.sh. BDR-093, LRN-158. Tests: profile-set-managed 17/17, make test green except 2 pre-existing gitflow FAILs (gitleaks binary absent on this host), shellcheck clean.
88 lines
3.9 KiB
TOML
88 lines
3.9 KiB
TOML
title = "claude-config gitleaks config"
|
|
|
|
# Backstop scanner (job7): pre-commit hook (lib/gitflow.sh emit-hook) and
|
|
# `make scan-secrets`. Extends gitleaks' default ruleset — never replaces it.
|
|
[extend]
|
|
useDefault = true
|
|
|
|
# 3 false-positive classes identified in job7 triage (.audit/job7/ALL-REDACTED.json),
|
|
# each verified empirically against the real flagged files before being added
|
|
# here (see .audit/job7-report.md). None of these are live secrets.
|
|
[[allowlists]]
|
|
description = "job7 triage — known false positives, not secrets"
|
|
|
|
# Content-based: git-game repo test fixtures (#5/#6 in the triage), confirmed
|
|
# synthetic by the repo owner — literal "test-secret-<digits>" values used in
|
|
# unit tests, flagged by the generic-api-key rule on entropy alone.
|
|
regexTarget = "match"
|
|
regexes = [
|
|
'''test-secret-[0-9-]+''',
|
|
]
|
|
|
|
# Path-based: third-party/vendored files outside our control, flagged by
|
|
# rules that don't apply to their content.
|
|
paths = [
|
|
# Official claude-plugins marketplace catalog — 40-char hex "sha" (git
|
|
# commit references, not credentials) trip the sourcegraph-access-token
|
|
# rule, which matches on bare hex length/entropy alone.
|
|
'''plugins/marketplaces/.*marketplace\.json$''',
|
|
# superpowers plugin test fixture — a base64-encoded WS protocol test
|
|
# nonce, not a credential, trips generic-api-key on entropy.
|
|
'''tests/brainstorm-server/ws-protocol\.test\.js$''',
|
|
# NOT a job7 false positive — this IS a real secret, by design: the
|
|
# canonical vault (BDR-026). `make scan-secrets` scans ~/.claude looking
|
|
# for stray COPIES of secrets outside this file; flagging the vault
|
|
# itself on every run is pure noise, not signal.
|
|
'''(^|/)\.env$''',
|
|
# seo-data OAuth token store — legitimate local secret (like ~/.claude/.env),
|
|
# 0600, outside git. Allowlisted so `make scan-secrets` doesn't flag the vault.
|
|
'''(^|/)\.claude/seo-data/tokens\.json$''',
|
|
]
|
|
|
|
# ── secrets-triage 2026-07-14 — 4 FP classes, each verified empirically
|
|
# (unredacted re-scan piped in-memory, values masked; see
|
|
# .gstack/security-reports/2026-07-14-secrets-triage.json). None are secrets.
|
|
# Transcripts and file-history are deliberately NOT path-allowlisted — that is
|
|
# where real leaks land (BDR-057).
|
|
|
|
# Bare 40-hex = git commit SHA (plugin-catalog pins, commit refs quoted in
|
|
# transcripts) tripping sourcegraph-access-token, which matches naked hex.
|
|
# Real sourcegraph tokens keep their sgp_ prefix → still detected.
|
|
[[allowlists]]
|
|
description = "bare 40-hex git commit SHAs (sourcegraph-access-token misfire)"
|
|
regexTarget = "secret"
|
|
regexes = ['''^[0-9a-f]{40}$''']
|
|
|
|
# Synthetic AWS key fabricated by lib/gitflow-test.sh:240 to exercise the
|
|
# pre-commit secret guard; test output lands in session transcripts.
|
|
[[allowlists]]
|
|
description = "gitflow-test synthetic AWS fixture (deliberately fake)"
|
|
regexTarget = "secret"
|
|
regexes = ['''AKIAGDR5XRBXYARW2I5N''']
|
|
|
|
# Public-by-design or expired URL credentials + documentation placeholders.
|
|
[[allowlists]]
|
|
description = "presigned-URL key ids, GitHub image JWTs, doc placeholders"
|
|
regexTarget = "line"
|
|
regexes = [
|
|
'''X-Amz-Credential=AKIA[0-9A-Z]{16}''',
|
|
'''private-user-images\.githubusercontent\.com/[^"]*\?jwt=''',
|
|
# Docs/test example — base64 of the "the ..." ASCII sample text, never a key.
|
|
# (The MAGIC_API_KEY=abc123 placeholder that sat here went with the magic
|
|
# MCP, removed 2026-09-22 when 21st.dev moved to a CLI with no API key.)
|
|
'''clientKey = 'dGhlIH[A-Za-z0-9+/=]*'''',
|
|
]
|
|
|
|
# Prose in transcripts near the word "tokens" — dictionary phrases flagged by
|
|
# generic-api-key on entropy alone (e.g. a design discussion of publish/reject
|
|
# token pairs). Exact literals only; transcripts stay fully scanned otherwise.
|
|
[[allowlists]]
|
|
description = "prose false positives in transcripts"
|
|
stopwords = ['''publish/reject''']
|
|
|
|
# Ephemeral machine-local IDE auth locks (rotate per IDE session, never leave
|
|
# the machine).
|
|
[[allowlists]]
|
|
description = "Claude Code IDE lock files"
|
|
paths = ['''(^|/)ide/[0-9]+\.lock$''']
|