mirror of
https://github.com/superdesigndev/treg.git
synced 2026-10-02 03:24:35 +08:00
* feat(cli): add anonymous PostHog usage telemetry * fix(ci): recognize public PostHog ingestion token * fix(ci): match ingestion token in historical diff lines * release: 0.18.0 * fix(cli): allow cold SDK imports within telemetry exit budget
67 lines
4.2 KiB
TOML
67 lines
4.2 KiB
TOML
# gitleaks config for tools-registry.
|
|
# We run gitleaks in CI (see .github/workflows/ci.yml) so no real secret can be committed. The entries
|
|
# below allowlist the handful of OBVIOUSLY-FAKE placeholder strings the code and tests use on purpose
|
|
# (redaction fixtures + the sandbox demo values) so they don't trip the scanner.
|
|
|
|
[extend]
|
|
useDefault = true
|
|
|
|
[allowlist]
|
|
description = "Fake, non-secret placeholders used by tests and the demo sandbox"
|
|
regexTarget = "line"
|
|
regexes = [
|
|
# Deliberately invalid ContactOut connect-test token; also present in branch history.
|
|
'''"token": "treg-intentionally-invalid-20260908",\s*$''',
|
|
'''sk_live_DEMO0000PLACEHOLDER''', # src/treg/sandbox.py — demo starter (credential to nothing)
|
|
'''phx_DEMO0000PLACEHOLDER''', # src/treg/sandbox.py — demo starter (credential to nothing)
|
|
'''sk_live_ABCDEFGHIJKLMNOP1234''', # tests/test_localrun.py — proves output redaction masks a key
|
|
'''sk_test_123''', # tests/*.py — generic fake test key
|
|
# IndexNow site keys are PUBLIC BY DESIGN: the protocol requires publishing the key at
|
|
# https://<site>/<key>.txt, so anyone can read it — proving site ownership is its whole job.
|
|
# The scanner reads every fetched branch, so the seo branch carrying treg's key as a constant
|
|
# turned the WHOLE repository's CI red. Shape-anchored to the IndexNow names/context only — a
|
|
# random new high-entropy constant elsewhere still fails the scan.
|
|
'''INDEXNOW_KEY\s*=''',
|
|
'''KEY\s*=\s*"[A-Za-z0-9-]{8,64}"\s*#\s*must match INDEXNOW_KEY''',
|
|
# (sk_live_9f2a7c41… lived here for tests/test_error_capture.py. That test now reuses the
|
|
# sk_live_ABCDEFGHIJKLMNOP1234 placeholder two lines up — one entry serving both tests that need a
|
|
# key-shaped string — and the old value is purged from history, so the entry had nothing to guard.)
|
|
'''eyJhbGciOi\.JIUzI1NiIsInR5cCI6''', # tests/test_error_capture.py — a JWT-shaped string, not a real token
|
|
]
|
|
|
|
# The catalog's captured example responses (src/treg/catalog/examples/) are real provider replies,
|
|
# and providers hand back long opaque identifiers by the hundred: video ids, request ids, CDN
|
|
# paths, ranking hints. Entropy alone cannot tell those from a credential, so the generic entropy
|
|
# rules fire on ordinary data there.
|
|
#
|
|
# What keeps that directory safe is upstream of this file, not in it: values under a
|
|
# credential-shaped key are redacted at capture time, session and cursor artifacts are dropped
|
|
# (they expire in minutes and document nothing), scripts/catalog_validate.py scans the whole
|
|
# catalog for credential shapes on every run, and docs/context/architecture/catalog.md states the
|
|
# rules curation follows. The scoping below is therefore narrow — the entropy rules only, in that
|
|
# one directory. Every provider-prefixed rule (Stripe, GitHub, Slack, Apify …) still applies there.
|
|
[[rules]]
|
|
id = "generic-api-key"
|
|
[rules.allowlist]
|
|
paths = ['''src/treg/catalog/examples/.*\.json''']
|
|
# The IndexNow key (scripts/indexnow_submit.py, routers/web.py) is PUBLIC by design: the protocol
|
|
# proves domain ownership by serving the key at https://<host>/<key>.txt, so anyone can read it and
|
|
# it authorises nothing but "submit URLs for this host". Matched by the line, not the value, so a
|
|
# real credential on the same line shape elsewhere still fires.
|
|
regexTarget = "line"
|
|
regexes = [
|
|
'''INDEXNOW_KEY\s*=|#\s*must match INDEX''',
|
|
# Public PostHog ingestion token from https://treg.to/meta, not a personal API key.
|
|
# Match this exact assignment only; other PostHog keys still trigger the scanner.
|
|
'''POSTHOG_KEY = "phc_sAgf5A7TPRRA6faCzuqGVUo8pyb3x5Nq7TJYfn6ZVif9"''',
|
|
]
|
|
# (An allowlist entry for a real dev/e2e Fernet key lived here as a stopgap while
|
|
# `feat/error-capture` carried it in `e2e-server.sh`. That branch now generates a fresh key per run
|
|
# — the harness deletes its database between runs, so it never needed a constant — and the value has
|
|
# been purged from its history, so the rule has nothing left to fire on. Removed as that entry's own
|
|
# comment instructed. The value is still burned: rotate it in the `treg-dev-server` wrapper.)
|
|
|
|
[[rules]]
|
|
id = "linkedin-client-id"
|
|
[rules.allowlist]
|
|
paths = ['''src/treg/catalog/.*'''] |