Repository navigation
Expand file tree
/
Copy path.gitleaks.toml
More file actions
46 lines (43 loc) · 1.43 KB
/
Copy path.gitleaks.toml
File metadata and controls
46 lines (43 loc) · 1.43 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
title = "stealthy-auto-browse secret scanning"
[extend]
useDefault = true
# `gitleaks dir` scans the working tree rather than Git's tracked-file set.
# These paths are already ignored local state; path allowlists keep the release
# gate focused on files that can actually ship.
[[allowlists]]
description = "Ignored local state and release tooling"
paths = [
'''(^|/)\.mypy_cache(?:/|$)''',
'''(^|/)__pycache__(?:/|$)''',
'''(^|/)AGENTS\.md$''',
'''(^|/)\.research_files(?:/|$)''',
'''(^|/)app/profile(?:/|$)''',
'''(^|/)CLAUDE\.md$''',
'''(^|/)screenshot\.png$''',
'''(^|/)\.testdata(?:/|$)''',
'''(^|/)\.git-update\.sh$''',
'''(^|/)ANUSTIMES\.md$''',
'''(^|/)research_files(?:/|$)''',
'''(^|/)reply\.txt$''',
'''(^|/)git-update\.sh$''',
'''(^|/)\.claude(?:/|$)''',
'''(^|/)lasttest\.log$''',
'''(^|/)tests/results(?:/|$)''',
'''(^|/)plan\.md$''',
'''(^|/)\.demo-recordings(?:/|$)''',
'''(^|/)\.telemetry(?:/|$)''',
'''(^|/)\.testing(?:/|$)''',
'''(^|/)\.anustimes(?:/|$)''',
'''(^|/)\.brutal_reviews(?:/|$)''',
'''(^|/)\.secaudit(?:/|$)''',
'''(^|/)\.plan-and-delegate(?:/|$)''',
]
# These are visibly fake documentation/test values, not credentials. Keep this
# exact-value exemption narrow: a real bearer value in either tracked file must
# still fail the release gate.
[[allowlists]]
description = "Explicit fake bearer-token examples"
regexes = [
'''your-token-here''',
'''wrong-token-not-a-secret''',
]