2 Commits
Author SHA1 Message Date
bmottin 740c3d8c3e Merge chore/gitleaks-allowlist-runtime-state into develop 2026-09-15 22:04:36 -04:00
bmottin e59e26890e chore(gitleaks): allowlist Claude Code daemon roster + per-session keys
`make scan-secrets` flagged 4 generic-api-key hits in ~/.claude, all written
by Claude Code itself: roster.json's rendezvousSock/ptySock unix-socket paths
and sessionId UUID (long, high-entropy, not credentials), and two per-worker
session keys (0600). Same class as the ide/*.lock entry above — machine-local,
ephemeral, and unreachable from a commit: link.sh exposes exactly seven repo
symlinks under ~/.claude and neither daemon/ nor sessions/ is among them, so
`git ls-files` can never see them.

Left unfixed they would redden every sweep, which is the failure mode the
.env entry already argues against — a permanently red scan stops being read.

Scoped to the two exact filenames rather than the directories, and verified:
fake secrets planted beside them in the same dirs are still caught, and the
repo's own history stays clean (745 commits, no leaks).
2026-09-15 22:01:50 -04:00
+17
View File
@@ -84,3 +84,20 @@ stopwords = ['''publish/reject''']
[[allowlists]] [[allowlists]]
description = "Claude Code IDE lock files" description = "Claude Code IDE lock files"
paths = ['''(^|/)ide/[0-9]+\.lock$'''] paths = ['''(^|/)ide/[0-9]+\.lock$''']
# ── 2026-09-15 — Claude Code daemon/session runtime state, triaged on macOS.
# Same class as the IDE locks above: written by Claude Code itself, machine-
# local, ephemeral. Verified before allowlisting — roster.json's hits are the
# rendezvousSock/ptySock unix-socket paths and the sessionId UUID (paths, not
# credentials); sessions/*.key IS a real per-worker key, but 0600 and outside
# git. Neither directory is reachable from a commit: link.sh exposes exactly
# seven repo symlinks under ~/.claude (CLAUDE.md, settings.json, hooks, agents,
# skills, lib, templates) and these are not among them, so `git ls-files` can
# never see them. Scoped to the two exact filenames, NOT to the directories —
# a stray copy landing beside them stays detected.
[[allowlists]]
description = "Claude Code daemon roster + per-session keys (machine-local runtime state)"
paths = [
'''(^|/)\.claude/daemon/roster\.json$''',
'''(^|/)\.claude/sessions/[0-9]+\.[0-9a-f]{64}\.key$''',
]