forked from bchanot/claude
chore(audit): untrack gitleaks reports; allowlist triaged FP classes
Reports are gitignored (.gitignore:94) but were swept into 17bdd08 —
even redacted they map secret types/locations for anyone with repo
access. Allowlists from the 2026-07-14 cso triage (75 findings → 0,
each class verified empirically): bare 40-hex git SHAs, gitflow-test
synthetic AWS fixture, presigned-URL key ids, expired GitHub image
JWTs, doc placeholders, IDE lock files, two prose literals. Converted
deprecated [allowlist] to [[allowlists]] (gitleaks 8.30 refuses the
mix). Makefile hint no longer suggests committing the reports.
Transcripts/file-history deliberately NOT path-allowlisted (BDR-057).
This commit is contained in:
@@ -48,7 +48,7 @@ scan-secrets: ## Gitleaks sweep: this repo's history + ~/.claude (job7 backstop)
|
||||
echo "== $$r (git history) =="; \
|
||||
gitleaks git "$$r" -c .gitleaks.toml --no-banner --redact -f json -r ".audit/scan-secrets-$$(basename "$$r").json" || fail=1; \
|
||||
done; \
|
||||
echo "Reports: .audit/scan-secrets-*.json (already redacted — safe to inspect/commit)"; \
|
||||
echo "Reports: .audit/scan-secrets-*.json (redacted; gitignored — keep local, do NOT commit)"; \
|
||||
exit $$fail
|
||||
|
||||
profile: ## Run profile.sh (usage: make profile cmd="set design")
|
||||
|
||||
Reference in New Issue
Block a user