diff --git a/.gitguardian.yaml b/.gitguardian.yaml new file mode 100644 index 0000000..26ceb18 --- /dev/null +++ b/.gitguardian.yaml @@ -0,0 +1,14 @@ +# Secret-scan policy. Written by agent-kit's secret_scan.py; extend it by hand, narrowly. +# +# ggshield reads this file (pre-commit, CI, local scans). The GitGuardian GitHub App, which posts +# the "GitGuardian Security Checks" run on pull requests, does not: its exclusions live in the +# GitGuardian dashboard (Settings -> Secrets detection -> Exclusion rules). +# +# Only named fixture and example-env paths are ignored. Never src/, never a real .env, never a +# detector. secret_scan.py still searches these paths for live-format keys. If a finding is real, +# rotate it first and then remove it; never add it here. +version: 2 +secret: + ignored_paths: + - "**/.env.example" + - "**/*.example" diff --git a/.gitleaks.toml b/.gitleaks.toml new file mode 100644 index 0000000..c33cb03 --- /dev/null +++ b/.gitleaks.toml @@ -0,0 +1,13 @@ +# gitleaks policy. Written by agent-kit's secret_scan.py; extend it by hand, narrowly. +# Only named fixture and example-env paths are allowlisted; secret_scan.py still +# searches them for live-format keys. A realistic fake elsewhere carries an inline +# `gitleaks:allow` comment instead. +[extend] +useDefault = true + +[[allowlists]] +description = "Named fixture and example-env paths (agent-kit secret_scan.py)" +paths = [ + '''^(?:.*/)?\.env\.example$''', + '''^(?:.*/)?[^/]*\.example$''', +]