Files
holocron/.gitleaks.toml
Defame1297 ac8235ca58 fix(gitleaks): suppress Token routing false positive; sync allowlists; update roadmap
gitleaks false positive (U1, Gitea issue #2):
- 'Token routing: Haiku/Sonnet/Opus' in ai-coding-factory-session.md:90
  triggers generic-api-key on entropy match of "Token". Not a credential.
- ROADMAP.md now documents this pattern and triggers the same rule.
- Both .gitleaks.toml (deployed, read by hook) and scripts/gitleaks.toml
  (source for setup-gitleaks.sh deploys) updated and aligned. Previously
  out of sync — deployed file had docs/research/.* already; source did not.

ROADMAP.md: governance workstream Phase 2 expanded with 7 immediately-
actionable test suite gaps and 5 Chunk 6 CI gaps, all mapped to
CONTROLS.md requirements. Housekeeping updated with audit entry.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gv5iNACZxumtF2k6TsK18q
2026-06-21 01:33:34 +00:00

34 lines
1.2 KiB
TOML

title = "gitleaks config"
[extend]
# Extends the default ruleset built into gitleaks.
# Remove useDefault and define [[rules]] from scratch if you want full control.
useDefault = true
# Rules to disable from the default set — uncomment and add IDs for known false positives.
# Run `gitleaks git -v` on your repo first to discover which rules fire.
# disabledRules = ["generic-api-key"]
# Project-specific allowlists — entries here apply to all rules.
# Add fingerprints from .gitleaksignore, or path/regex patterns to suppress noise.
#
# Example: ignore test fixtures
# [[allowlists]]
# description = "test fixtures"
# paths = ['''tests/fixtures/.*''']
#
# Example: ignore a known false-positive secret value
# [[allowlists]]
# description = "placeholder values used in docs"
# stopwords = ["example", "placeholder", "changeme"]
[allowlist]
description = "Known false positives — prose patterns and research session notes"
# docs/research/: high-entropy text from terminal captures in session notes
# docs/ROADMAP.md: documents known false positives, triggering the same rules
# ai-coding-factory-session.md:90 specifically: 'Token routing: Haiku/Sonnet/Opus'
paths = [
'''docs/research/.*''',
'''docs/ROADMAP\.md''',
]