Repository navigation
Expand file tree
/
Copy path.gitleaks.toml
More file actions
46 lines (41 loc) · 2.11 KB
/
Copy path.gitleaks.toml
File metadata and controls
46 lines (41 loc) · 2.11 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
# Canonical gitleaks config for WAVE public repos.
#
# This file is VENDORED into each repo alongside the public-repo-guard workflow,
# which runs `gitleaks detect --no-git --source . --config .gitleaks.toml` over the
# checked-out tree. It extends gitleaks' built-in rule set (which already covers
# Stripe, AWS, GitHub, Slack, private keys, etc.) and adds an allowlist so obvious
# placeholders / fixtures / examples do not produce false BLOCKs. A repo may extend
# this with its own rules, but should not weaken the credential patterns.
#
# Pair this with scripts/public-repo-guard/content-policy.sh, which catches the
# WAVE-specific things gitleaks does NOT: live Stripe account IDs, hardcoded CF
# account_ids, developer absolute paths, and private-repo references.
title = "WAVE public-repo gitleaks config"
[extend]
useDefault = true
[allowlist]
description = "Placeholders, templates, and test fixtures that are not real secrets"
# Paths that are documentation examples or test fixtures by construction.
paths = [
'''(^|/)\.git/''', # git metadata (packed-refs, objects) — not source, avoids --no-git FPs
'''(^|/)\.gitleaks\.toml$''',
'''(^|/)scripts/public-repo-guard/''',
'''(^|/)(test|tests|__tests__|fixtures|__fixtures__|testdata|examples?|samples?|spec)/''', # testdata/ = Go-conventional fixtures dir (holds published test vectors, e.g. Hardhat keys)
'''\.(test|spec)\.[jt]sx?$''', # co-located unit tests (foo.test.ts / foo.spec.tsx) — fixtures, not secrets
'''\.(example|sample|template|dist)$''',
'''(^|/)(.+\.)?env\.(example|sample|template)$''',
]
# Obvious non-secret tokens: redacted blobs, doc placeholders, and template vars.
regexes = [
'''(?i)\b(example|placeholder|your[-_]?|my[-_]?|dummy|fake|test|sample|redacted|changeme|xxxx+|\.\.\.|<[^>]+>)\b''',
'''\{\{[^}]+\}\}''', # mustache/handlebars template vars, e.g. {{passphrase}}
'''\$\{?[A-Z][A-Z0-9_]+\}?''', # env-var references, e.g. $CLOUDFLARE_ACCOUNT_ID
]
# Common doc stopwords that appear inside otherwise secret-shaped strings.
stopwords = [
"example",
"placeholder",
"redacted",
"your-",
"changeme",
]