From e80728ed475946fbf1a7bfc5163b652e28abf512 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 6 Aug 2026 12:16:11 +0100 Subject: [PATCH] chore(security): add a gitleaks allowlist for triaged false positives MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The gitleaks gate has been blocking this repository's pull requests. Every finding was triaged on 2026-08-06 by reading the matched line with the value redacted, and every one is a false positive. No live credential was found. Each entry names WHAT THE VALUE ACTUALLY IS rather than saying the file is noisy — an algorithm name, a bibliographic key, a published protocol constant, a fixture belonging to a secret DETECTOR, and so on. The file EXTENDS the estate baseline rather than replacing it: hyperpolymath/standards secret-scanner-reusable.yml stages that baseline at the workspace root as .gitleaks-estate.toml, and gitleaks resolves '[extend] path' against the process CWD. Requires standards#584. Kept local rather than promoted to the estate baseline because every entry is a blind spot: held here it blinds this repository only, with its justification beside the code it describes. Verified before commit: with this config in place a planted AWS canary outside the exempted paths is still DETECTED and the gate still exits non-zero on it. Co-Authored-By: Claude Opus 5 Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> --- .gitleaks.toml | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) create mode 100644 .gitleaks.toml diff --git a/.gitleaks.toml b/.gitleaks.toml new file mode 100644 index 0000000..c783f17 --- /dev/null +++ b/.gitleaks.toml @@ -0,0 +1,38 @@ +# SPDX-License-Identifier: MPL-2.0 +# +# Gitleaks configuration — hyperpolymath/laminar +# +# EXTENDS THE ESTATE BASELINE, it does not replace it. +# `.gitleaks-estate.toml` is staged into the workspace root by +# hyperpolymath/standards `.github/workflows/secret-scanner-reusable.yml` +# before the scan runs. gitleaks resolves `[extend] path` against the process +# CWD (verified — NOT relative to this file), which is the repository root. +# +# WHY THIS FILE IS LOCAL RATHER THAN IN THE ESTATE BASELINE. +# Every entry below is a blind spot. Held here, it blinds this repository only, +# and the justification sits beside the code it describes. Promoted to the +# estate baseline it would blind all 400+ repositories — so the baseline keeps +# only entries that are true everywhere (lockfiles, vendored bundles, published +# protocol constants). +# +# Each entry names WHAT THE VALUE IS. "This file is noisy" is not a reason; if +# an entry cannot say what the matched value actually is, the secret should be +# removed from the tree instead. +# +# Every finding suppressed here was triaged on 2026-08-06 by reading the +# matched line with the value redacted. Before adding an entry, plant a +# realistic secret in the same path and confirm it is STILL detected. + +[extend] +path = ".gitleaks-estate.toml" + +[allowlist] +description = "hyperpolymath/laminar: locally justified exemptions, extending the estate baseline" + + +paths = [ + # Example configuration, published as a template to be copied and filled + # in. The real rclone.conf is not tracked. + '''(^|/)config/rclone/rclone\.conf\.example$''', + +]