feat(security): Add gitleaks secret scanning to prevent API key leaks
After a real API key leaked through test files with realistic hex patterns, this adds automated secret detection: .gitleaks.toml with custom rules for OpenRouter/OpenAI/Anthropic/Google keys, and .pre-commit-config.yaml wiring gitleaks as a pre-commit hook. Test keys locally updated to use FAKE-/NOTREAL conventions that pass the allowlist. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
aba5cc32bd
commit
fc2e9daccc
@@ -0,0 +1,67 @@
|
||||
# Gitleaks configuration for AIPass
|
||||
# Prevents API keys and secrets from being committed to the repo.
|
||||
#
|
||||
# Usage: gitleaks runs automatically via pre-commit hook.
|
||||
# Manual scan: gitleaks detect --config .gitleaks.toml
|
||||
|
||||
title = "AIPass Secret Detection Rules"
|
||||
|
||||
[extend]
|
||||
useDefault = true
|
||||
|
||||
# --- Custom rules for AIPass-specific key formats ---
|
||||
|
||||
[[rules]]
|
||||
id = "openrouter-api-key"
|
||||
description = "OpenRouter API key (sk-or-v1- prefix with 20+ alphanumeric chars)"
|
||||
regex = '''sk-or-v1-[a-zA-Z0-9]{20,}'''
|
||||
keywords = ["sk-or-v1-"]
|
||||
|
||||
[[rules]]
|
||||
id = "openai-api-key"
|
||||
description = "OpenAI API key (sk- prefix with 20+ chars, not sk-or/sk-ant)"
|
||||
regex = '''sk-(?!or|ant)[a-zA-Z0-9]{20,}'''
|
||||
keywords = ["sk-"]
|
||||
|
||||
[[rules]]
|
||||
id = "anthropic-api-key"
|
||||
description = "Anthropic API key (sk-ant- prefix)"
|
||||
regex = '''sk-ant-[a-zA-Z0-9]{20,}'''
|
||||
keywords = ["sk-ant-"]
|
||||
|
||||
[[rules]]
|
||||
id = "google-api-key"
|
||||
description = "Google API key (AIza prefix)"
|
||||
regex = '''AIza[0-9A-Za-z\-_]{35,}'''
|
||||
keywords = ["AIza"]
|
||||
|
||||
[[rules]]
|
||||
id = "bearer-token-in-code"
|
||||
description = "Bearer token hardcoded in source (not in test assertions)"
|
||||
regex = '''Bearer\s+[a-zA-Z0-9_\-\.]{40,}'''
|
||||
keywords = ["Bearer"]
|
||||
|
||||
[[rules]]
|
||||
id = "env-file-key-assignment"
|
||||
description = "API key assigned in code with realistic value"
|
||||
regex = '''(?:OPENROUTER|OPENAI|ANTHROPIC|GOOGLE)_API_KEY\s*=\s*["']?(?:sk-|AIza)[a-zA-Z0-9\-_]{20,}'''
|
||||
keywords = ["API_KEY"]
|
||||
|
||||
# --- Allowlists ---
|
||||
|
||||
[allowlist]
|
||||
# Files that are allowed to contain key-like patterns
|
||||
paths = [
|
||||
'''\.gitleaks\.toml$''',
|
||||
'''\.pre-commit-config\.yaml$''',
|
||||
]
|
||||
|
||||
# Strings that are explicitly allowed (FAKE/NOTREAL test keys, prefix patterns)
|
||||
regexes = [
|
||||
'''FAKE-''',
|
||||
'''NOTREAL''',
|
||||
'''your-key-here''',
|
||||
'''your-openai-key-here''',
|
||||
'''sk-or-v1-short''',
|
||||
'''sk-wrong-prefix''',
|
||||
]
|
||||
@@ -0,0 +1,10 @@
|
||||
# Pre-commit hooks for AIPass
|
||||
# Install: pip install pre-commit && pre-commit install
|
||||
# Manual run: pre-commit run --all-files
|
||||
|
||||
repos:
|
||||
# Gitleaks — secret detection
|
||||
- repo: https://github.com/gitleaks/gitleaks
|
||||
rev: v8.21.2
|
||||
hooks:
|
||||
- id: gitleaks
|
||||
Reference in New Issue
Block a user