forked from bchanot/claude
Pre-commit (lib/gitflow.sh emit-hook) now runs `gitleaks git --staged` right after the root-commit/merge-in-progress guard, on ANY branch — not gated by branch protection, since secrets shouldn't land anywhere. Non-blocking if gitleaks isn't installed (warn + pass). gitleaks 8.30.1: `protect` isn't listed in --help anymore (still runs, but undocumented) — used the documented `git --staged` equivalent instead. .gitleaks.toml allowlists the 3 false-positive classes from the job7 triage (marketplace.json 40-hex "sha" fields, superpowers ws-protocol.test.js nonce, git-game test-secret-* fixtures) plus a 4th entry for ~/.claude/.env itself — not a false positive, but scanning our own canonical vault (BDR-026) is pure noise for a tool meant to catch stray copies. All 4 verified empirically against the real flagged files/values before being added, not assumed from gitleaks' docs. `make scan-secrets` scans this repo's git history + ~/.claude (dir scan), redacted JSON to .audit/ (verified: --redact scrubs Match/Secret in the report itself, not just console logs — safe to commit). Repo: 0 findings. ~/.claude: 18 remaining across 8 files — 5 match the known job7 triage (pending the GO-gated purge in step D), 3 are new discoveries outside the original triage scope (flagged for the user, not characterized further — never read a flagged file's content past what gitleaks' redacted report gives you). lib/gitflow-test.sh T16: fake secret on a feature branch (not main/develop) → blocked, proving the check isn't gated by branch protection; clean commit passes; PATH without gitleaks → warns and still commits. 96/96 green.
38 lines
1.7 KiB
TOML
38 lines
1.7 KiB
TOML
title = "claude-config gitleaks config"
|
|
|
|
# Backstop scanner (job7): pre-commit hook (lib/gitflow.sh emit-hook) and
|
|
# `make scan-secrets`. Extends gitleaks' default ruleset — never replaces it.
|
|
[extend]
|
|
useDefault = true
|
|
|
|
# 3 false-positive classes identified in job7 triage (.audit/job7/ALL-REDACTED.json),
|
|
# each verified empirically against the real flagged files before being added
|
|
# here (see .audit/job7-report.md). None of these are live secrets.
|
|
[allowlist]
|
|
description = "job7 triage — known false positives, not secrets"
|
|
|
|
# Content-based: git-game repo test fixtures (#5/#6 in the triage), confirmed
|
|
# synthetic by the repo owner — literal "test-secret-<digits>" values used in
|
|
# unit tests, flagged by the generic-api-key rule on entropy alone.
|
|
regexTarget = "match"
|
|
regexes = [
|
|
'''test-secret-[0-9-]+''',
|
|
]
|
|
|
|
# Path-based: third-party/vendored files outside our control, flagged by
|
|
# rules that don't apply to their content.
|
|
paths = [
|
|
# Official claude-plugins marketplace catalog — 40-char hex "sha" (git
|
|
# commit references, not credentials) trip the sourcegraph-access-token
|
|
# rule, which matches on bare hex length/entropy alone.
|
|
'''plugins/marketplaces/.*marketplace\.json$''',
|
|
# superpowers plugin test fixture — a base64-encoded WS protocol test
|
|
# nonce, not a credential, trips generic-api-key on entropy.
|
|
'''tests/brainstorm-server/ws-protocol\.test\.js$''',
|
|
# NOT a job7 false positive — this IS a real secret, by design: the
|
|
# canonical vault (BDR-026). `make scan-secrets` scans ~/.claude looking
|
|
# for stray COPIES of secrets outside this file; flagging the vault
|
|
# itself on every run is pure noise, not signal.
|
|
'''(^|/)\.env$''',
|
|
]
|