forked from bchanot/claude
job7 step C: gitleaks backstop — .gitleaks.toml, pre-commit hook, make scan-secrets
Pre-commit (lib/gitflow.sh emit-hook) now runs `gitleaks git --staged` right after the root-commit/merge-in-progress guard, on ANY branch — not gated by branch protection, since secrets shouldn't land anywhere. Non-blocking if gitleaks isn't installed (warn + pass). gitleaks 8.30.1: `protect` isn't listed in --help anymore (still runs, but undocumented) — used the documented `git --staged` equivalent instead. .gitleaks.toml allowlists the 3 false-positive classes from the job7 triage (marketplace.json 40-hex "sha" fields, superpowers ws-protocol.test.js nonce, git-game test-secret-* fixtures) plus a 4th entry for ~/.claude/.env itself — not a false positive, but scanning our own canonical vault (BDR-026) is pure noise for a tool meant to catch stray copies. All 4 verified empirically against the real flagged files/values before being added, not assumed from gitleaks' docs. `make scan-secrets` scans this repo's git history + ~/.claude (dir scan), redacted JSON to .audit/ (verified: --redact scrubs Match/Secret in the report itself, not just console logs — safe to commit). Repo: 0 findings. ~/.claude: 18 remaining across 8 files — 5 match the known job7 triage (pending the GO-gated purge in step D), 3 are new discoveries outside the original triage scope (flagged for the user, not characterized further — never read a flagged file's content past what gitleaks' redacted report gives you). lib/gitflow-test.sh T16: fake secret on a feature branch (not main/develop) → blocked, proving the check isn't gated by branch protection; clean commit passes; PATH without gitleaks → warns and still commits. 96/96 green.
This commit is contained in:
@@ -0,0 +1,368 @@
|
||||
[
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 5,
|
||||
"EndLine": 5,
|
||||
"StartColumn": 2,
|
||||
"EndColumn": 66,
|
||||
"Match": "AWS_SECRET_ACCESS_KEY = \"REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 5.009636,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2:generic-api-key:5"
|
||||
},
|
||||
{
|
||||
"RuleID": "stripe-access-token",
|
||||
"Description": "Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.",
|
||||
"StartLine": 3,
|
||||
"EndLine": 3,
|
||||
"StartColumn": 19,
|
||||
"EndColumn": 57,
|
||||
"Match": "REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 4.807009,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2:stripe-access-token:3"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 1,
|
||||
"EndLine": 1,
|
||||
"StartColumn": 112,
|
||||
"EndColumn": 160,
|
||||
"Match": "authToken\":\"REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/ide/20429.lock",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.7873018,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/ide/20429.lock:generic-api-key:1"
|
||||
},
|
||||
{
|
||||
"RuleID": "sourcegraph-access-token",
|
||||
"Description": "Sourcegraph is a code search and navigation engine.",
|
||||
"StartLine": 579,
|
||||
"EndLine": 579,
|
||||
"StartColumn": 17,
|
||||
"EndColumn": 57,
|
||||
"Match": "REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.6628149,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt:sourcegraph-access-token:579"
|
||||
},
|
||||
{
|
||||
"RuleID": "sourcegraph-access-token",
|
||||
"Description": "Sourcegraph is a code search and navigation engine.",
|
||||
"StartLine": 590,
|
||||
"EndLine": 590,
|
||||
"StartColumn": 17,
|
||||
"EndColumn": 57,
|
||||
"Match": "REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.7275672,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt:sourcegraph-access-token:590"
|
||||
},
|
||||
{
|
||||
"RuleID": "github-pat",
|
||||
"Description": "Uncovered a GitHub Personal Access Token, potentially leading to unauthorized repository access and sensitive content exposure.",
|
||||
"StartLine": 194,
|
||||
"EndLine": 194,
|
||||
"StartColumn": 469,
|
||||
"EndColumn": 508,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/27758e8c-36b5-4816-8141-8b07ba28b0c8.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 4.6841836,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/27758e8c-36b5-4816-8141-8b07ba28b0c8.jsonl:github-pat:194"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 10,
|
||||
"EndLine": 10,
|
||||
"StartColumn": 676,
|
||||
"EndColumn": 730,
|
||||
"Match": "nGITEA_TOKEN=REDACTED\\n",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/960bd2cf-7915-479e-a9d7-616a463789f9.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.7282128,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/960bd2cf-7915-479e-a9d7-616a463789f9.jsonl:generic-api-key:10"
|
||||
},
|
||||
{
|
||||
"RuleID": "jwt",
|
||||
"Description": "Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.",
|
||||
"StartLine": 164,
|
||||
"EndLine": 164,
|
||||
"StartColumn": 18186,
|
||||
"EndColumn": 18851,
|
||||
"Match": "REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/d71e6b88-7632-40e9-b7bc-830fb32fc464/tool-results/bsl3i4eop.txt",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 5.639867,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/d71e6b88-7632-40e9-b7bc-830fb32fc464/tool-results/bsl3i4eop.txt:jwt:164"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 652,
|
||||
"EndLine": 652,
|
||||
"StartColumn": 275,
|
||||
"EndColumn": 294,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.5464394,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 652,
|
||||
"EndLine": 652,
|
||||
"StartColumn": 671,
|
||||
"EndColumn": 690,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.5464394,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 46,
|
||||
"EndLine": 46,
|
||||
"StartColumn": 358,
|
||||
"EndColumn": 395,
|
||||
"Match": "clientKey = 'REDACTED'",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 4.168296,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:46"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 46,
|
||||
"EndLine": 46,
|
||||
"StartColumn": 733,
|
||||
"EndColumn": 770,
|
||||
"Match": "clientKey = 'REDACTED'",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 4.168296,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:46"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 52,
|
||||
"EndLine": 52,
|
||||
"StartColumn": 543,
|
||||
"EndColumn": 562,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.821928,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 52,
|
||||
"EndLine": 52,
|
||||
"StartColumn": 1175,
|
||||
"EndColumn": 1194,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.821928,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 52,
|
||||
"EndLine": 52,
|
||||
"StartColumn": 543,
|
||||
"EndColumn": 1225,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.821928,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [
|
||||
"decoded:percent",
|
||||
"decode-depth:1"
|
||||
],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 52,
|
||||
"EndLine": 52,
|
||||
"StartColumn": 563,
|
||||
"EndColumn": 1225,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.821928,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [
|
||||
"decoded:percent",
|
||||
"decode-depth:1"
|
||||
],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 112,
|
||||
"EndLine": 112,
|
||||
"StartColumn": 3505,
|
||||
"EndColumn": 3542,
|
||||
"Match": "clientKey = 'REDACTED'",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 4.168296,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:112"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 121,
|
||||
"EndLine": 121,
|
||||
"StartColumn": 2059,
|
||||
"EndColumn": 2096,
|
||||
"Match": "clientKey = 'REDACTED'",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 4.168296,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:121"
|
||||
}
|
||||
]
|
||||
Reference in New Issue
Block a user