chore(audit): untrack gitleaks reports; allowlist triaged FP classes

Reports are gitignored (.gitignore:94) but were swept into 17bdd08 —
even redacted they map secret types/locations for anyone with repo
access. Allowlists from the 2026-07-14 cso triage (75 findings → 0,
each class verified empirically): bare 40-hex git SHAs, gitflow-test
synthetic AWS fixture, presigned-URL key ids, expired GitHub image
JWTs, doc placeholders, IDE lock files, two prose literals. Converted
deprecated [allowlist] to [[allowlists]] (gitleaks 8.30 refuses the
mix). Makefile hint no longer suggests committing the reports.
Transcripts/file-history deliberately NOT path-allowlisted (BDR-057).
This commit is contained in:
Bastien Chanot
2026-07-14 18:07:11 +02:00
parent b7106761b0
commit 20b90465d8
4 changed files with 48 additions and 311 deletions
-308
View File
@@ -1,308 +0,0 @@
[
{
"RuleID": "generic-api-key",
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
"StartLine": 5,
"EndLine": 5,
"StartColumn": 2,
"EndColumn": 66,
"Match": "AWS_SECRET_ACCESS_KEY = \"REDACTED\"",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2",
"SymlinkFile": "",
"Commit": "",
"Entropy": 5.009636,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2:generic-api-key:5"
},
{
"RuleID": "stripe-access-token",
"Description": "Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.",
"StartLine": 3,
"EndLine": 3,
"StartColumn": 19,
"EndColumn": 57,
"Match": "REDACTED\"",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2",
"SymlinkFile": "",
"Commit": "",
"Entropy": 4.807009,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2:stripe-access-token:3"
},
{
"RuleID": "generic-api-key",
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
"StartLine": 1,
"EndLine": 1,
"StartColumn": 112,
"EndColumn": 160,
"Match": "authToken\":\"REDACTED\"",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/ide/20429.lock",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.7873018,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/ide/20429.lock:generic-api-key:1"
},
{
"RuleID": "github-pat",
"Description": "Uncovered a GitHub Personal Access Token, potentially leading to unauthorized repository access and sensitive content exposure.",
"StartLine": 194,
"EndLine": 194,
"StartColumn": 469,
"EndColumn": 508,
"Match": "REDACTED",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/27758e8c-36b5-4816-8141-8b07ba28b0c8.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 4.6841836,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/27758e8c-36b5-4816-8141-8b07ba28b0c8.jsonl:github-pat:194"
},
{
"RuleID": "jwt",
"Description": "Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.",
"StartLine": 164,
"EndLine": 164,
"StartColumn": 18186,
"EndColumn": 18851,
"Match": "REDACTED\"",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/d71e6b88-7632-40e9-b7bc-830fb32fc464/tool-results/bsl3i4eop.txt",
"SymlinkFile": "",
"Commit": "",
"Entropy": 5.639867,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/d71e6b88-7632-40e9-b7bc-830fb32fc464/tool-results/bsl3i4eop.txt:jwt:164"
},
{
"RuleID": "generic-api-key",
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
"StartLine": 46,
"EndLine": 46,
"StartColumn": 358,
"EndColumn": 395,
"Match": "clientKey = 'REDACTED'",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 4.168296,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:46"
},
{
"RuleID": "generic-api-key",
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
"StartLine": 46,
"EndLine": 46,
"StartColumn": 733,
"EndColumn": 770,
"Match": "clientKey = 'REDACTED'",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 4.168296,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:46"
},
{
"RuleID": "aws-access-token",
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
"StartLine": 52,
"EndLine": 52,
"StartColumn": 543,
"EndColumn": 562,
"Match": "REDACTED",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.821928,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
},
{
"RuleID": "aws-access-token",
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
"StartLine": 52,
"EndLine": 52,
"StartColumn": 1175,
"EndColumn": 1194,
"Match": "REDACTED",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.821928,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
},
{
"RuleID": "aws-access-token",
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
"StartLine": 52,
"EndLine": 52,
"StartColumn": 543,
"EndColumn": 1225,
"Match": "REDACTED",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.821928,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [
"decoded:percent",
"decode-depth:1"
],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
},
{
"RuleID": "aws-access-token",
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
"StartLine": 52,
"EndLine": 52,
"StartColumn": 563,
"EndColumn": 1225,
"Match": "REDACTED",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.821928,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [
"decoded:percent",
"decode-depth:1"
],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
},
{
"RuleID": "aws-access-token",
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
"StartLine": 652,
"EndLine": 652,
"StartColumn": 275,
"EndColumn": 294,
"Match": "REDACTED",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.5464394,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
},
{
"RuleID": "aws-access-token",
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
"StartLine": 652,
"EndLine": 652,
"StartColumn": 671,
"EndColumn": 690,
"Match": "REDACTED",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.5464394,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
},
{
"RuleID": "generic-api-key",
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
"StartLine": 112,
"EndLine": 112,
"StartColumn": 3505,
"EndColumn": 3542,
"Match": "clientKey = 'REDACTED'",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 4.168296,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:112"
},
{
"RuleID": "generic-api-key",
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
"StartLine": 121,
"EndLine": 121,
"StartColumn": 2059,
"EndColumn": 2096,
"Match": "clientKey = 'REDACTED'",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 4.168296,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:121"
}
]
-1
View File
@@ -1 +0,0 @@
[]
+47 -1
View File
@@ -8,7 +8,7 @@ useDefault = true
# 3 false-positive classes identified in job7 triage (.audit/job7/ALL-REDACTED.json),
# each verified empirically against the real flagged files before being added
# here (see .audit/job7-report.md). None of these are live secrets.
[allowlist]
[[allowlists]]
description = "job7 triage — known false positives, not secrets"
# Content-based: git-game repo test fixtures (#5/#6 in the triage), confirmed
@@ -38,3 +38,49 @@ paths = [
# 0600, outside git. Allowlisted so `make scan-secrets` doesn't flag the vault.
'''(^|/)\.claude/seo-data/tokens\.json$''',
]
# ── secrets-triage 2026-07-14 — 4 FP classes, each verified empirically
# (unredacted re-scan piped in-memory, values masked; see
# .gstack/security-reports/2026-07-14-secrets-triage.json). None are secrets.
# Transcripts and file-history are deliberately NOT path-allowlisted — that is
# where real leaks land (BDR-057).
# Bare 40-hex = git commit SHA (plugin-catalog pins, commit refs quoted in
# transcripts) tripping sourcegraph-access-token, which matches naked hex.
# Real sourcegraph tokens keep their sgp_ prefix → still detected.
[[allowlists]]
description = "bare 40-hex git commit SHAs (sourcegraph-access-token misfire)"
regexTarget = "secret"
regexes = ['''^[0-9a-f]{40}$''']
# Synthetic AWS key fabricated by lib/gitflow-test.sh:240 to exercise the
# pre-commit secret guard; test output lands in session transcripts.
[[allowlists]]
description = "gitflow-test synthetic AWS fixture (deliberately fake)"
regexTarget = "secret"
regexes = ['''AKIAGDR5XRBXYARW2I5N''']
# Public-by-design or expired URL credentials + documentation placeholders.
[[allowlists]]
description = "presigned-URL key ids, GitHub image JWTs, doc placeholders"
regexTarget = "line"
regexes = [
'''X-Amz-Credential=AKIA[0-9A-Z]{16}''',
'''private-user-images\.githubusercontent\.com/[^"]*\?jwt=''',
'''MAGIC_API_KEY=abc123''',
# magic MCP docs example — base64 of "the ..." ASCII sample text.
'''clientKey = 'dGhlIH[A-Za-z0-9+/=]*'''',
]
# Prose in transcripts near the word "tokens" — dictionary phrases flagged by
# generic-api-key on entropy alone (e.g. a design discussion of publish/reject
# token pairs). Exact literals only; transcripts stay fully scanned otherwise.
[[allowlists]]
description = "prose false positives in transcripts"
stopwords = ['''publish/reject''']
# Ephemeral machine-local IDE auth locks (rotate per IDE session, never leave
# the machine).
[[allowlists]]
description = "Claude Code IDE lock files"
paths = ['''(^|/)ide/[0-9]+\.lock$''']
+1 -1
View File
@@ -48,7 +48,7 @@ scan-secrets: ## Gitleaks sweep: this repo's history + ~/.claude (job7 backstop)
echo "== $$r (git history) =="; \
gitleaks git "$$r" -c .gitleaks.toml --no-banner --redact -f json -r ".audit/scan-secrets-$$(basename "$$r").json" || fail=1; \
done; \
echo "Reports: .audit/scan-secrets-*.json (already redacted — safe to inspect/commit)"; \
echo "Reports: .audit/scan-secrets-*.json (redacted; gitignored — keep local, do NOT commit)"; \
exit $$fail
profile: ## Run profile.sh (usage: make profile cmd="set design")