a11oy / .gitleaks.toml
betterwithage's picture
sync(space): full source mirror — resolve all GitHub<->Space drift (CTO)
a6a5d8e verified
Raw
History Blame
1.83 kB
# .gitleaks.toml — SZL Holdings secret-scanning allowlist.
#
# Doctrine v11 LOCKED 749/14/163 · SLSA L1 honest
# Signed-off-by: Yachay <yachay@szlholdings.ai>
# Co-Authored-By: Perplexity Computer Agent <agent@perplexity.ai>
#
# HONESTY OVER CHECKLIST: this file does NOT weaken secret detection. It uses
# the full upstream gitleaks default ruleset and only exempts demonstrable
# NON-secrets that the `generic-api-key` heuristic flags because they contain
# the substring "key":
#
# • did:key public DID identifiers (z6Mk… multibase) — public by definition
# • `keyid` labels (e.g. "szl-pepr-mldsa65-v1", "szlholdings-ec-p256") —
# these name a key, they are not key material
# • PLACEHOLDER / test signature stubs (sig bytes are 0xAB fill / "PLACEHOLDER")
#
# Real credentials (tokens, private keys, cloud secrets) remain fully detected.
[extend]
useDefault = true
[allowlist]
description = "SZL non-secret identifiers and test/placeholder stubs"
# Match the allowlist regexes against the whole matched line, so `keyid` labels
# and public DIDs are exempted regardless of how the rule captured them.
regexTarget = "line"
regexes = [
# Public DID key identifiers (did:key multibase, public by definition).
'''did:key:z6Mk[1-9A-HJ-NP-Za-km-z]+''',
# `keyid` / key-id LABELS — these NAME a key, they are not key material.
# Covers: keyid, SZL_KEY_ID, signing_key_id, key_id, listingKey (MLS listing id).
'''(?i)(keyid|key[_-]?id|signing_key_id|listingkey)["']?\s*[:=]\s*["'`]?[A-Za-z0-9._-]+["'`]?''',
# Explicit placeholder / unsigned stub markers.
'''PLACEHOLDER-NOT-SIGNED''',
]
# Test fixtures legitimately carry mock key identifiers and stub signatures.
paths = [
'''.*\.test\.ts$''',
'''.*__tests__/.*''',
'''.*_test\.py$''',
'''.*/test/.*''',
'''.*/tests/.*''',
]