diff --git a/.audit/scan-secrets-claude-home.json b/.audit/scan-secrets-claude-home.json deleted file mode 100644 index 869424d..0000000 --- a/.audit/scan-secrets-claude-home.json +++ /dev/null @@ -1,308 +0,0 @@ -[ - { - "RuleID": "generic-api-key", - "Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.", - "StartLine": 5, - "EndLine": 5, - "StartColumn": 2, - "EndColumn": 66, - "Match": "AWS_SECRET_ACCESS_KEY = \"REDACTED\"", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2", - "SymlinkFile": "", - "Commit": "", - "Entropy": 5.009636, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [], - "Fingerprint": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2:generic-api-key:5" - }, - { - "RuleID": "stripe-access-token", - "Description": "Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.", - "StartLine": 3, - "EndLine": 3, - "StartColumn": 19, - "EndColumn": 57, - "Match": "REDACTED\"", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2", - "SymlinkFile": "", - "Commit": "", - "Entropy": 4.807009, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [], - "Fingerprint": "/home/bchanot/.claude/file-history/27758e8c-36b5-4816-8141-8b07ba28b0c8/19af1df0732eefc6@v2:stripe-access-token:3" - }, - { - "RuleID": "generic-api-key", - "Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.", - "StartLine": 1, - "EndLine": 1, - "StartColumn": 112, - "EndColumn": 160, - "Match": "authToken\":\"REDACTED\"", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/ide/20429.lock", - "SymlinkFile": "", - "Commit": "", - "Entropy": 3.7873018, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [], - "Fingerprint": "/home/bchanot/.claude/ide/20429.lock:generic-api-key:1" - }, - { - "RuleID": "github-pat", - "Description": "Uncovered a GitHub Personal Access Token, potentially leading to unauthorized repository access and sensitive content exposure.", - "StartLine": 194, - "EndLine": 194, - "StartColumn": 469, - "EndColumn": 508, - "Match": "REDACTED", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/27758e8c-36b5-4816-8141-8b07ba28b0c8.jsonl", - "SymlinkFile": "", - "Commit": "", - "Entropy": 4.6841836, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [], - "Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/27758e8c-36b5-4816-8141-8b07ba28b0c8.jsonl:github-pat:194" - }, - { - "RuleID": "jwt", - "Description": "Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.", - "StartLine": 164, - "EndLine": 164, - "StartColumn": 18186, - "EndColumn": 18851, - "Match": "REDACTED\"", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/d71e6b88-7632-40e9-b7bc-830fb32fc464/tool-results/bsl3i4eop.txt", - "SymlinkFile": "", - "Commit": "", - "Entropy": 5.639867, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [], - "Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/d71e6b88-7632-40e9-b7bc-830fb32fc464/tool-results/bsl3i4eop.txt:jwt:164" - }, - { - "RuleID": "generic-api-key", - "Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.", - "StartLine": 46, - "EndLine": 46, - "StartColumn": 358, - "EndColumn": 395, - "Match": "clientKey = 'REDACTED'", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl", - "SymlinkFile": "", - "Commit": "", - "Entropy": 4.168296, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [], - "Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:46" - }, - { - "RuleID": "generic-api-key", - "Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.", - "StartLine": 46, - "EndLine": 46, - "StartColumn": 733, - "EndColumn": 770, - "Match": "clientKey = 'REDACTED'", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl", - "SymlinkFile": "", - "Commit": "", - "Entropy": 4.168296, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [], - "Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:46" - }, - { - "RuleID": "aws-access-token", - "Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.", - "StartLine": 52, - "EndLine": 52, - "StartColumn": 543, - "EndColumn": 562, - "Match": "REDACTED", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl", - "SymlinkFile": "", - "Commit": "", - "Entropy": 3.821928, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [], - "Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52" - }, - { - "RuleID": "aws-access-token", - "Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.", - "StartLine": 52, - "EndLine": 52, - "StartColumn": 1175, - "EndColumn": 1194, - "Match": "REDACTED", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl", - "SymlinkFile": "", - "Commit": "", - "Entropy": 3.821928, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [], - "Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52" - }, - { - "RuleID": "aws-access-token", - "Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.", - "StartLine": 52, - "EndLine": 52, - "StartColumn": 543, - "EndColumn": 1225, - "Match": "REDACTED", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl", - "SymlinkFile": "", - "Commit": "", - "Entropy": 3.821928, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [ - "decoded:percent", - "decode-depth:1" - ], - "Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52" - }, - { - "RuleID": "aws-access-token", - "Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.", - "StartLine": 52, - "EndLine": 52, - "StartColumn": 563, - "EndColumn": 1225, - "Match": "REDACTED", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl", - "SymlinkFile": "", - "Commit": "", - "Entropy": 3.821928, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [ - "decoded:percent", - "decode-depth:1" - ], - "Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52" - }, - { - "RuleID": "aws-access-token", - "Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.", - "StartLine": 652, - "EndLine": 652, - "StartColumn": 275, - "EndColumn": 294, - "Match": "REDACTED", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl", - "SymlinkFile": "", - "Commit": "", - "Entropy": 3.5464394, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [], - "Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652" - }, - { - "RuleID": "aws-access-token", - "Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.", - "StartLine": 652, - "EndLine": 652, - "StartColumn": 671, - "EndColumn": 690, - "Match": "REDACTED", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl", - "SymlinkFile": "", - "Commit": "", - "Entropy": 3.5464394, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [], - "Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652" - }, - { - "RuleID": "generic-api-key", - "Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.", - "StartLine": 112, - "EndLine": 112, - "StartColumn": 3505, - "EndColumn": 3542, - "Match": "clientKey = 'REDACTED'", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl", - "SymlinkFile": "", - "Commit": "", - "Entropy": 4.168296, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [], - "Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:112" - }, - { - "RuleID": "generic-api-key", - "Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.", - "StartLine": 121, - "EndLine": 121, - "StartColumn": 2059, - "EndColumn": 2096, - "Match": "clientKey = 'REDACTED'", - "Secret": "REDACTED", - "File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl", - "SymlinkFile": "", - "Commit": "", - "Entropy": 4.168296, - "Author": "", - "Email": "", - "Date": "", - "Message": "", - "Tags": [], - "Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:generic-api-key:121" - } -] diff --git a/.audit/scan-secrets-repo.json b/.audit/scan-secrets-repo.json deleted file mode 100644 index fe51488..0000000 --- a/.audit/scan-secrets-repo.json +++ /dev/null @@ -1 +0,0 @@ -[] diff --git a/.gitleaks.toml b/.gitleaks.toml index d11491c..7794295 100644 --- a/.gitleaks.toml +++ b/.gitleaks.toml @@ -8,7 +8,7 @@ useDefault = true # 3 false-positive classes identified in job7 triage (.audit/job7/ALL-REDACTED.json), # each verified empirically against the real flagged files before being added # here (see .audit/job7-report.md). None of these are live secrets. -[allowlist] +[[allowlists]] description = "job7 triage — known false positives, not secrets" # Content-based: git-game repo test fixtures (#5/#6 in the triage), confirmed @@ -38,3 +38,49 @@ paths = [ # 0600, outside git. Allowlisted so `make scan-secrets` doesn't flag the vault. '''(^|/)\.claude/seo-data/tokens\.json$''', ] + +# ── secrets-triage 2026-07-14 — 4 FP classes, each verified empirically +# (unredacted re-scan piped in-memory, values masked; see +# .gstack/security-reports/2026-07-14-secrets-triage.json). None are secrets. +# Transcripts and file-history are deliberately NOT path-allowlisted — that is +# where real leaks land (BDR-057). + +# Bare 40-hex = git commit SHA (plugin-catalog pins, commit refs quoted in +# transcripts) tripping sourcegraph-access-token, which matches naked hex. +# Real sourcegraph tokens keep their sgp_ prefix → still detected. +[[allowlists]] +description = "bare 40-hex git commit SHAs (sourcegraph-access-token misfire)" +regexTarget = "secret" +regexes = ['''^[0-9a-f]{40}$'''] + +# Synthetic AWS key fabricated by lib/gitflow-test.sh:240 to exercise the +# pre-commit secret guard; test output lands in session transcripts. +[[allowlists]] +description = "gitflow-test synthetic AWS fixture (deliberately fake)" +regexTarget = "secret" +regexes = ['''AKIAGDR5XRBXYARW2I5N'''] + +# Public-by-design or expired URL credentials + documentation placeholders. +[[allowlists]] +description = "presigned-URL key ids, GitHub image JWTs, doc placeholders" +regexTarget = "line" +regexes = [ + '''X-Amz-Credential=AKIA[0-9A-Z]{16}''', + '''private-user-images\.githubusercontent\.com/[^"]*\?jwt=''', + '''MAGIC_API_KEY=abc123''', + # magic MCP docs example — base64 of "the ..." ASCII sample text. + '''clientKey = 'dGhlIH[A-Za-z0-9+/=]*'''', +] + +# Prose in transcripts near the word "tokens" — dictionary phrases flagged by +# generic-api-key on entropy alone (e.g. a design discussion of publish/reject +# token pairs). Exact literals only; transcripts stay fully scanned otherwise. +[[allowlists]] +description = "prose false positives in transcripts" +stopwords = ['''publish/reject'''] + +# Ephemeral machine-local IDE auth locks (rotate per IDE session, never leave +# the machine). +[[allowlists]] +description = "Claude Code IDE lock files" +paths = ['''(^|/)ide/[0-9]+\.lock$'''] diff --git a/Makefile b/Makefile index 5f503b7..7002ce1 100644 --- a/Makefile +++ b/Makefile @@ -48,7 +48,7 @@ scan-secrets: ## Gitleaks sweep: this repo's history + ~/.claude (job7 backstop) echo "== $$r (git history) =="; \ gitleaks git "$$r" -c .gitleaks.toml --no-banner --redact -f json -r ".audit/scan-secrets-$$(basename "$$r").json" || fail=1; \ done; \ - echo "Reports: .audit/scan-secrets-*.json (already redacted — safe to inspect/commit)"; \ + echo "Reports: .audit/scan-secrets-*.json (redacted; gitignored — keep local, do NOT commit)"; \ exit $$fail profile: ## Run profile.sh (usage: make profile cmd="set design")