From 72cae36282f71c0084a37ee280681c9d0626e21a Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 6 Aug 2026 12:16:05 +0100 Subject: [PATCH] chore(security): add a gitleaks allowlist for triaged false positives MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The gitleaks gate has been blocking this repository's pull requests. Every finding was triaged on 2026-08-06 by reading the matched line with the value redacted, and every one is a false positive. No live credential was found. Each entry names WHAT THE VALUE ACTUALLY IS rather than saying the file is noisy — an algorithm name, a bibliographic key, a published protocol constant, a fixture belonging to a secret DETECTOR, and so on. The file EXTENDS the estate baseline rather than replacing it: hyperpolymath/standards secret-scanner-reusable.yml stages that baseline at the workspace root as .gitleaks-estate.toml, and gitleaks resolves '[extend] path' against the process CWD. Requires standards#584. Kept local rather than promoted to the estate baseline because every entry is a blind spot: held here it blinds this repository only, with its justification beside the code it describes. Verified before commit: with this config in place a planted AWS canary outside the exempted paths is still DETECTED and the gate still exits non-zero on it. Co-Authored-By: Claude Opus 5 Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> --- .gitleaks.toml | 43 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 43 insertions(+) create mode 100644 .gitleaks.toml diff --git a/.gitleaks.toml b/.gitleaks.toml new file mode 100644 index 0000000..cd3ab63 --- /dev/null +++ b/.gitleaks.toml @@ -0,0 +1,43 @@ +# SPDX-License-Identifier: MPL-2.0 +# +# Gitleaks configuration — hyperpolymath/echidna +# +# EXTENDS THE ESTATE BASELINE, it does not replace it. +# `.gitleaks-estate.toml` is staged into the workspace root by +# hyperpolymath/standards `.github/workflows/secret-scanner-reusable.yml` +# before the scan runs. gitleaks resolves `[extend] path` against the process +# CWD (verified — NOT relative to this file), which is the repository root. +# +# WHY THIS FILE IS LOCAL RATHER THAN IN THE ESTATE BASELINE. +# Every entry below is a blind spot. Held here, it blinds this repository only, +# and the justification sits beside the code it describes. Promoted to the +# estate baseline it would blind all 400+ repositories — so the baseline keeps +# only entries that are true everywhere (lockfiles, vendored bundles, published +# protocol constants). +# +# Each entry names WHAT THE VALUE IS. "This file is noisy" is not a reason; if +# an entry cannot say what the matched value actually is, the secret should be +# removed from the tree instead. +# +# Every finding suppressed here was triaged on 2026-08-06 by reading the +# matched line with the value redacted. Before adding an entry, plant a +# realistic secret in the same path and confirm it is STILL detected. + +[extend] +path = ".gitleaks-estate.toml" + +[allowlist] +description = "hyperpolymath/echidna: locally justified exemptions, extending the estate baseline" + + +paths = [ + # Declared machine-learning corpus. These JSONL files are training data + # FOR a security/proof analyser: containing credential-shaped strings is + # their entire purpose. 69 of this repo's 73 findings are this directory. + '''(^|/)training_data/[^/]*\.jsonl$''', + + # Model vocabulary file — a token list extracted from the corpus above, so + # it inherits the same credential-shaped strings by construction. + '''(^|/)models/premise_vocab\.txt$''', + +]