The default `curl-auth-header` rule flags lines like
`Authorization: token invalid_token` in demo markdown files. The
forthcoming demos/multi-tenant-http.md (commit bd08d6147 on the
byteflavour/stateless-token fork branch) demonstrates the "request
with invalid token" path and trips the scan on import.
Add a per-rule allowlist on `curl-auth-header` scoped to:
- path: `demos/.*\.md$`
- secret matches one of: invalid_token, placeholder_token, changeme,
your(_api)?_token_here (case-insensitive, anchored)
A real-looking token in the same file is still detected by the
`github-pat` rule, verified locally with gitleaks v8.30.1.
Gotcha discovered: gitleaks v8.30.x ignores user-added `[[rules]]`
blocks that appear AFTER any top-level `[[allowlists]]` in the same
file. Per-rule allowlists must come first.
Refs forgejo-mcp-dhd.
32 lines
760 B
TOML
32 lines
760 B
TOML
[extend]
|
|
useDefault = true
|
|
|
|
[[rules]]
|
|
id = "generic-api-key"
|
|
|
|
[[rules.allowlists]]
|
|
condition = "AND"
|
|
paths = ['''(?i).*\.ya?ml$''']
|
|
regexes = ['''^Ag[a-zA-Z0-9+/]{500,}={0,2}$''']
|
|
|
|
[[rules]]
|
|
id = "curl-auth-header"
|
|
|
|
[[rules.allowlists]]
|
|
description = "Placeholder tokens in demo docs"
|
|
condition = "AND"
|
|
paths = ['''demos/.*\.md$''']
|
|
regexes = [
|
|
'''(?i)^invalid[-_]?token$''',
|
|
'''(?i)^placeholder[-_]?token$''',
|
|
'''(?i)^changeme$''',
|
|
'''(?i)^your[-_](api[-_])?token[-_]here$''',
|
|
]
|
|
|
|
[[allowlists]]
|
|
description = "Historical commits with rotated credentials; pre-existing residue, not in current main."
|
|
commits = [
|
|
"0eac698f002763f5b0b862fc1f919f6d4e4e259d",
|
|
"17cf298ea16665599627fe765db6b60766eb9851",
|
|
"86351a10cee44caf36979984f42196964189314d",
|
|
]
|