forked from bchanot/claude
job7 step C: gitleaks backstop — .gitleaks.toml, pre-commit hook, make scan-secrets
Pre-commit (lib/gitflow.sh emit-hook) now runs `gitleaks git --staged` right after the root-commit/merge-in-progress guard, on ANY branch — not gated by branch protection, since secrets shouldn't land anywhere. Non-blocking if gitleaks isn't installed (warn + pass). gitleaks 8.30.1: `protect` isn't listed in --help anymore (still runs, but undocumented) — used the documented `git --staged` equivalent instead. .gitleaks.toml allowlists the 3 false-positive classes from the job7 triage (marketplace.json 40-hex "sha" fields, superpowers ws-protocol.test.js nonce, git-game test-secret-* fixtures) plus a 4th entry for ~/.claude/.env itself — not a false positive, but scanning our own canonical vault (BDR-026) is pure noise for a tool meant to catch stray copies. All 4 verified empirically against the real flagged files/values before being added, not assumed from gitleaks' docs. `make scan-secrets` scans this repo's git history + ~/.claude (dir scan), redacted JSON to .audit/ (verified: --redact scrubs Match/Secret in the report itself, not just console logs — safe to commit). Repo: 0 findings. ~/.claude: 18 remaining across 8 files — 5 match the known job7 triage (pending the GO-gated purge in step D), 3 are new discoveries outside the original triage scope (flagged for the user, not characterized further — never read a flagged file's content past what gitleaks' redacted report gives you). lib/gitflow-test.sh T16: fake secret on a feature branch (not main/develop) → blocked, proving the check isn't gated by branch protection; clean commit passes; PATH without gitleaks → warns and still commits. 96/96 green.
This commit is contained in:
@@ -0,0 +1,368 @@
|
||||
[
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 5,
|
||||
"EndLine": 5,
|
||||
"StartColumn": 2,
|
||||
"EndColumn": 66,
|
||||
"Match": "AWS_SECRET_ACCESS_KEY = \"REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 5.009636,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2:generic-api-key:5"
|
||||
},
|
||||
{
|
||||
"RuleID": "stripe-access-token",
|
||||
"Description": "Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.",
|
||||
"StartLine": 3,
|
||||
"EndLine": 3,
|
||||
"StartColumn": 19,
|
||||
"EndColumn": 57,
|
||||
"Match": "REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 4.807009,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2:stripe-access-token:3"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 1,
|
||||
"EndLine": 1,
|
||||
"StartColumn": 112,
|
||||
"EndColumn": 160,
|
||||
"Match": "authToken\":\"REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/ide/20429.lock",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.7873018,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/ide/20429.lock:generic-api-key:1"
|
||||
},
|
||||
{
|
||||
"RuleID": "sourcegraph-access-token",
|
||||
"Description": "Sourcegraph is a code search and navigation engine.",
|
||||
"StartLine": 579,
|
||||
"EndLine": 579,
|
||||
"StartColumn": 17,
|
||||
"EndColumn": 57,
|
||||
"Match": "REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.6628149,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt:sourcegraph-access-token:579"
|
||||
},
|
||||
{
|
||||
"RuleID": "sourcegraph-access-token",
|
||||
"Description": "Sourcegraph is a code search and navigation engine.",
|
||||
"StartLine": 590,
|
||||
"EndLine": 590,
|
||||
"StartColumn": 17,
|
||||
"EndColumn": 57,
|
||||
"Match": "REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.7275672,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt:sourcegraph-access-token:590"
|
||||
},
|
||||
{
|
||||
"RuleID": "github-pat",
|
||||
"Description": "Uncovered a GitHub Personal Access Token, potentially leading to unauthorized repository access and sensitive content exposure.",
|
||||
"StartLine": 194,
|
||||
"EndLine": 194,
|
||||
"StartColumn": 469,
|
||||
"EndColumn": 508,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/27758e8c-36b5-4816-8141-8b07ba28b0c8.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 4.6841836,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/27758e8c-36b5-4816-8141-8b07ba28b0c8.jsonl:github-pat:194"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 10,
|
||||
"EndLine": 10,
|
||||
"StartColumn": 676,
|
||||
"EndColumn": 730,
|
||||
"Match": "nGITEA_TOKEN=REDACTED\\n",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/960bd2cf-7915-479e-a9d7-616a463789f9.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.7282128,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/960bd2cf-7915-479e-a9d7-616a463789f9.jsonl:generic-api-key:10"
|
||||
},
|
||||
{
|
||||
"RuleID": "jwt",
|
||||
"Description": "Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.",
|
||||
"StartLine": 164,
|
||||
"EndLine": 164,
|
||||
"StartColumn": 18186,
|
||||
"EndColumn": 18851,
|
||||
"Match": "REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/d71e6b88-7632-40e9-b7bc-830fb32fc464/tool-results/bsl3i4eop.txt",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 5.639867,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/d71e6b88-7632-40e9-b7bc-830fb32fc464/tool-results/bsl3i4eop.txt:jwt:164"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 652,
|
||||
"EndLine": 652,
|
||||
"StartColumn": 275,
|
||||
"EndColumn": 294,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.5464394,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 652,
|
||||
"EndLine": 652,
|
||||
"StartColumn": 671,
|
||||
"EndColumn": 690,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.5464394,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 46,
|
||||
"EndLine": 46,
|
||||
"StartColumn": 358,
|
||||
"EndColumn": 395,
|
||||
"Match": "clientKey = 'REDACTED'",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 4.168296,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:46"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 46,
|
||||
"EndLine": 46,
|
||||
"StartColumn": 733,
|
||||
"EndColumn": 770,
|
||||
"Match": "clientKey = 'REDACTED'",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 4.168296,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:46"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 52,
|
||||
"EndLine": 52,
|
||||
"StartColumn": 543,
|
||||
"EndColumn": 562,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.821928,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 52,
|
||||
"EndLine": 52,
|
||||
"StartColumn": 1175,
|
||||
"EndColumn": 1194,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.821928,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 52,
|
||||
"EndLine": 52,
|
||||
"StartColumn": 543,
|
||||
"EndColumn": 1225,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.821928,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [
|
||||
"decoded:percent",
|
||||
"decode-depth:1"
|
||||
],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 52,
|
||||
"EndLine": 52,
|
||||
"StartColumn": 563,
|
||||
"EndColumn": 1225,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.821928,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [
|
||||
"decoded:percent",
|
||||
"decode-depth:1"
|
||||
],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 112,
|
||||
"EndLine": 112,
|
||||
"StartColumn": 3505,
|
||||
"EndColumn": 3542,
|
||||
"Match": "clientKey = 'REDACTED'",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 4.168296,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:112"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 121,
|
||||
"EndLine": 121,
|
||||
"StartColumn": 2059,
|
||||
"EndColumn": 2096,
|
||||
"Match": "clientKey = 'REDACTED'",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 4.168296,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:121"
|
||||
}
|
||||
]
|
||||
@@ -0,0 +1 @@
|
||||
[]
|
||||
+33
-13
@@ -48,22 +48,42 @@ manipuler une valeur de secret — edits sur les mécanismes seulement.
|
||||
[A-Za-z_]*)=.*/\1=REDACTED/'`. `env VAR=x cmd` intact. Compound bail
|
||||
(`;`/`&`/`||`) — jamais de pipe attaché au mauvais segment.
|
||||
- [x] `lib/tests/rtk-rewrite.test.sh` — 3 cas + garde compound
|
||||
- [ ] `make test` vert
|
||||
- [ ] C. Backstop gitleaks (8.30.1 confirmé installé — `protect` non listé,
|
||||
`gitleaks git --staged` = sous-commande documentée retenue)
|
||||
- [ ] `.gitleaks.toml` racine — allowlist 3 classes (vérifiées empiriquement
|
||||
contre les vrais fichiers : marketplace.json sha 40-hex, ws-protocol
|
||||
nonce, test-secret-[0-9-]+)
|
||||
- [ ] pre-commit gitflow (`lib/gitflow.sh` `_gitflow_emit_pre_commit`) —
|
||||
- [x] `make test` vert (96/96 gitflow-test + suite complète)
|
||||
- [x] C. Backstop gitleaks (8.30.1 confirmé installé — `protect` non listé
|
||||
dans `--help` mais fonctionne encore ; `gitleaks git --staged` =
|
||||
sous-commande documentée retenue à la place)
|
||||
- [x] `.gitleaks.toml` racine — allowlist 3 classes job7 (vérifiées
|
||||
empiriquement contre les vrais fichiers : marketplace.json sha
|
||||
40-hex, ws-protocol nonce, test-secret-[0-9-]+) + 4e entrée
|
||||
`(^|/)\.env$` (pas un faux positif — c'est le vault canonique
|
||||
BDR-026 ; exclu du bruit, pas de la détection)
|
||||
- [x] pre-commit gitflow (`lib/gitflow.sh` `_gitflow_emit_pre_commit`) —
|
||||
`gitleaks git --staged` après guard root/merge, non-bloquant si absent
|
||||
- [ ] `lib/gitflow-test.sh` — faux secret staged bloqué ; PATH sans gitleaks
|
||||
→ warn + pass
|
||||
- [ ] `make scan-secrets` — git × repos + dir ~/.claude, sortie → `.audit/`
|
||||
- [ ] D. Purge (GO explicite par item)
|
||||
- [ ] transcript 960bd2cf…jsonl — propose rm, attend GO
|
||||
- [ ] `ide/27929.lock` stale — rm direct
|
||||
- [x] `lib/gitflow-test.sh` T16 — faux secret (AKIA random) sur feature
|
||||
branch → bloqué ; commit propre passe ; PATH sans gitleaks → warn
|
||||
+ pass. 96/96 vert.
|
||||
- [x] `make scan-secrets` — repo (git history) + dir ~/.claude, redacted
|
||||
JSON → `.audit/` (`--redact` vérifié : Match/Secret redacted dans
|
||||
le report, pas juste les logs). Repo : 0 (attendu). ~/.claude : 18
|
||||
hits restants, 8 fichiers — voir D (5 déjà dans le triage job7,
|
||||
3 NOUVEAUX non couverts par la spec initiale, à trancher)
|
||||
- [ ] D. Purge (GO explicite par item) — état réel après `make scan-secrets` :
|
||||
- [ ] transcript 960bd2cf…jsonl (generic-api-key) — propose rm, attend GO
|
||||
- [x] `ide/27929.lock` — déjà rotée toute seule (fichier absent, session
|
||||
finie). REMPLACÉE par `ide/20429.lock` (NOUVEAU, session active en
|
||||
cours) — NE PAS rm (verrou live) ; candidat allowlist de classe
|
||||
(`ide/*.lock` structurel, pas un secret) si le pattern se confirme
|
||||
- [ ] `cleanupPeriodDays` — vérifier nom exact champ doc, proposer 7j, diff
|
||||
settings avant écriture
|
||||
- [ ] **NOUVEAU (hors spec initiale, découvert par `make scan-secrets`)** :
|
||||
`paste-cache/7d48f52c7499c1a7.txt` (sourcegraph-access-token, 2) ;
|
||||
transcript `f1c9c474-...jsonl` (generic-api-key, 8) — ni lus ni
|
||||
caractérisés plus avant (règle job7 : jamais manipuler une valeur).
|
||||
Décision utilisateur requise avant toute action.
|
||||
- [x] **NOUVEAU (bruit, pas un item D)** : transcript de CETTE session
|
||||
(`4b5c02a9-...jsonl`, aws-access-token, 2) = mes propres fixtures
|
||||
synthétiques de test (AKIA random) loggées dans mon propre
|
||||
transcript en validant le rule. Pas un vrai secret, rien à purger.
|
||||
- [ ] Gate final : `make test` + `make scan-secrets` propre + table
|
||||
étape/commit/gate + capitalize (BDR secrets-par-référence, MAJ BDR-026,
|
||||
LRN piège `claude mcp add --env`)
|
||||
|
||||
@@ -0,0 +1,37 @@
|
||||
title = "claude-config gitleaks config"
|
||||
|
||||
# Backstop scanner (job7): pre-commit hook (lib/gitflow.sh emit-hook) and
|
||||
# `make scan-secrets`. Extends gitleaks' default ruleset — never replaces it.
|
||||
[extend]
|
||||
useDefault = true
|
||||
|
||||
# 3 false-positive classes identified in job7 triage (.audit/job7/ALL-REDACTED.json),
|
||||
# each verified empirically against the real flagged files before being added
|
||||
# here (see .audit/job7-report.md). None of these are live secrets.
|
||||
[allowlist]
|
||||
description = "job7 triage — known false positives, not secrets"
|
||||
|
||||
# Content-based: git-game repo test fixtures (#5/#6 in the triage), confirmed
|
||||
# synthetic by the repo owner — literal "test-secret-<digits>" values used in
|
||||
# unit tests, flagged by the generic-api-key rule on entropy alone.
|
||||
regexTarget = "match"
|
||||
regexes = [
|
||||
'''test-secret-[0-9-]+''',
|
||||
]
|
||||
|
||||
# Path-based: third-party/vendored files outside our control, flagged by
|
||||
# rules that don't apply to their content.
|
||||
paths = [
|
||||
# Official claude-plugins marketplace catalog — 40-char hex "sha" (git
|
||||
# commit references, not credentials) trip the sourcegraph-access-token
|
||||
# rule, which matches on bare hex length/entropy alone.
|
||||
'''plugins/marketplaces/.*marketplace\.json$''',
|
||||
# superpowers plugin test fixture — a base64-encoded WS protocol test
|
||||
# nonce, not a credential, trips generic-api-key on entropy.
|
||||
'''tests/brainstorm-server/ws-protocol\.test\.js$''',
|
||||
# NOT a job7 false positive — this IS a real secret, by design: the
|
||||
# canonical vault (BDR-026). `make scan-secrets` scans ~/.claude looking
|
||||
# for stray COPIES of secrets outside this file; flagging the vault
|
||||
# itself on every run is pure noise, not signal.
|
||||
'''(^|/)\.env$''',
|
||||
]
|
||||
@@ -1,4 +1,4 @@
|
||||
.PHONY: help install plugin link doctor update new-skill profile profile-list profile-current profile-reset onboard test
|
||||
.PHONY: help install plugin link doctor update new-skill profile profile-list profile-current profile-reset onboard test scan-secrets
|
||||
|
||||
help: ## Show available commands
|
||||
@grep -E '^[a-zA-Z_-]+:.*##' $(MAKEFILE_LIST) | awk 'BEGIN {FS = ":.*## "}; {printf " make %-14s %s\n", $$1, $$2}'
|
||||
@@ -30,6 +30,21 @@ test: ## Run deterministic tests (lib/tests/*.test.sh + lib/gitflow-test.sh + li
|
||||
*) bash "$$t" || fail=1 ;; \
|
||||
esac; done; exit $$fail
|
||||
|
||||
scan-secrets: ## Gitleaks sweep: this repo's history + ~/.claude (job7 backstop). Extra repos: make scan-secrets repos="path1 path2"
|
||||
@command -v gitleaks >/dev/null 2>&1 || { echo "gitleaks not installed — https://github.com/gitleaks/gitleaks"; exit 1; }
|
||||
@mkdir -p .audit
|
||||
@fail=0; \
|
||||
echo "== this repo (git history) =="; \
|
||||
gitleaks git . -c .gitleaks.toml --no-banner --redact -f json -r .audit/scan-secrets-repo.json || fail=1; \
|
||||
echo "== ~/.claude (dir scan) =="; \
|
||||
gitleaks dir "$$HOME/.claude" -c .gitleaks.toml --no-banner --redact -f json -r .audit/scan-secrets-claude-home.json || fail=1; \
|
||||
for r in $(repos); do \
|
||||
echo "== $$r (git history) =="; \
|
||||
gitleaks git "$$r" -c .gitleaks.toml --no-banner --redact -f json -r ".audit/scan-secrets-$$(basename "$$r").json" || fail=1; \
|
||||
done; \
|
||||
echo "Reports: .audit/scan-secrets-*.json (already redacted — safe to inspect/commit)"; \
|
||||
exit $$fail
|
||||
|
||||
profile: ## Run profile.sh (usage: make profile cmd="set design")
|
||||
@bash lib/profile.sh $(cmd)
|
||||
|
||||
|
||||
@@ -231,6 +231,31 @@ chk "T15 nothing staged" '[ -z "$(git diff --cached --name-only)" ]'
|
||||
chk "T15 no .gitignore written" '[ ! -e .gitignore ]'
|
||||
chk "T15 no .githooks written" '[ ! -d .githooks ]'
|
||||
|
||||
echo "T16 — gitleaks pre-commit backstop (job7), independent of branch protection"
|
||||
newrepo gl; echo a>a; hookon; gitflow_init >/dev/null 2>&1
|
||||
gitflow_start feature glwork >/dev/null 2>&1
|
||||
|
||||
# T16a — a real secret pattern staged on a working branch (not main/develop,
|
||||
# proving this backstop is NOT gated by the branch-protection check above it)
|
||||
printf 'aws_access_key_id = AKIA%s\n' "GDR5XRBXYARW2I5N" > secret.txt
|
||||
git add secret.txt
|
||||
gl_out="$(git commit -q -m "add secret" 2>&1)"; gl_rc=$?
|
||||
chk "T16a fake secret on feature branch → blocked" "[ $gl_rc -ne 0 ]"
|
||||
chk "T16a message mentions gitleaks" 'printf "%s" "$gl_out" | grep -qi gitleaks'
|
||||
chk "T16a nothing committed" '! git log --oneline 2>/dev/null | grep -q "add secret"'
|
||||
git restore --staged secret.txt 2>/dev/null || true; rm -f secret.txt
|
||||
|
||||
# T16b — a clean commit is unaffected
|
||||
echo clean > clean.txt; git add clean.txt
|
||||
chk "T16b clean commit still succeeds" 'git commit -q -m "clean work" 2>/dev/null'
|
||||
|
||||
# T16c — gitleaks missing from PATH → warn, never block (defense in depth
|
||||
# must not become a new single point of failure)
|
||||
echo clean2 > clean2.txt; git add clean2.txt
|
||||
noleaks_out="$(PATH=/usr/bin:/bin git commit -q -m "clean work 2" 2>&1)"; noleaks_rc=$?
|
||||
chk "T16c missing-gitleaks → still commits (rc0)" "[ $noleaks_rc -eq 0 ]"
|
||||
chk "T16c missing-gitleaks → warns" 'printf "%s" "$noleaks_out" | grep -qi "not installed"'
|
||||
|
||||
echo
|
||||
echo "==== RESULT: $PASS passed, $FAIL failed ===="
|
||||
[ "$FAIL" -eq 0 ]
|
||||
|
||||
@@ -221,6 +221,19 @@ br=\$(git symbolic-ref --short -q HEAD 2>/dev/null)
|
||||
git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — allow
|
||||
[ -f "\$gd/MERGE_HEAD" ] && exit 0 # merge in progress — allow
|
||||
|
||||
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
||||
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
||||
if command -v gitleaks >/dev/null 2>&1; then
|
||||
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then
|
||||
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
||||
echo " Details: gitleaks git --staged --no-banner" >&2
|
||||
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "gitflow pre-commit: gitleaks not installed — secret scan skipped (https://github.com/gitleaks/gitleaks)." >&2
|
||||
fi
|
||||
|
||||
case "\$br" in
|
||||
$GITFLOW_MAIN|$GITFLOW_DEVELOP) ;; # protected — keep checking
|
||||
*) exit 0 ;; # working branch — allow
|
||||
|
||||
Reference in New Issue
Block a user