feat(security): Add gitleaks secret scanning to prevent API key leaks

After a real API key leaked through test files with realistic hex patterns,
this adds automated secret detection: .gitleaks.toml with custom rules for
OpenRouter/OpenAI/Anthropic/Google keys, and .pre-commit-config.yaml wiring
gitleaks as a pre-commit hook. Test keys locally updated to use FAKE-/NOTREAL
conventions that pass the allowlist.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
AIOSAI
2026-04-10 04:16:50 -07:00
co-authored by Claude Opus 4.6
parent aba5cc32bd
commit fc2e9daccc
2 changed files with 77 additions and 0 deletions
+67
View File
@@ -0,0 +1,67 @@
# Gitleaks configuration for AIPass
# Prevents API keys and secrets from being committed to the repo.
#
# Usage: gitleaks runs automatically via pre-commit hook.
# Manual scan: gitleaks detect --config .gitleaks.toml
title = "AIPass Secret Detection Rules"
[extend]
useDefault = true
# --- Custom rules for AIPass-specific key formats ---
[[rules]]
id = "openrouter-api-key"
description = "OpenRouter API key (sk-or-v1- prefix with 20+ alphanumeric chars)"
regex = '''sk-or-v1-[a-zA-Z0-9]{20,}'''
keywords = ["sk-or-v1-"]
[[rules]]
id = "openai-api-key"
description = "OpenAI API key (sk- prefix with 20+ chars, not sk-or/sk-ant)"
regex = '''sk-(?!or|ant)[a-zA-Z0-9]{20,}'''
keywords = ["sk-"]
[[rules]]
id = "anthropic-api-key"
description = "Anthropic API key (sk-ant- prefix)"
regex = '''sk-ant-[a-zA-Z0-9]{20,}'''
keywords = ["sk-ant-"]
[[rules]]
id = "google-api-key"
description = "Google API key (AIza prefix)"
regex = '''AIza[0-9A-Za-z\-_]{35,}'''
keywords = ["AIza"]
[[rules]]
id = "bearer-token-in-code"
description = "Bearer token hardcoded in source (not in test assertions)"
regex = '''Bearer\s+[a-zA-Z0-9_\-\.]{40,}'''
keywords = ["Bearer"]
[[rules]]
id = "env-file-key-assignment"
description = "API key assigned in code with realistic value"
regex = '''(?:OPENROUTER|OPENAI|ANTHROPIC|GOOGLE)_API_KEY\s*=\s*["']?(?:sk-|AIza)[a-zA-Z0-9\-_]{20,}'''
keywords = ["API_KEY"]
# --- Allowlists ---
[allowlist]
# Files that are allowed to contain key-like patterns
paths = [
'''\.gitleaks\.toml$''',
'''\.pre-commit-config\.yaml$''',
]
# Strings that are explicitly allowed (FAKE/NOTREAL test keys, prefix patterns)
regexes = [
'''FAKE-''',
'''NOTREAL''',
'''your-key-here''',
'''your-openai-key-here''',
'''sk-or-v1-short''',
'''sk-wrong-prefix''',
]
+10
View File
@@ -0,0 +1,10 @@
# Pre-commit hooks for AIPass
# Install: pip install pre-commit && pre-commit install
# Manual run: pre-commit run --all-files
repos:
# Gitleaks — secret detection
- repo: https://github.com/gitleaks/gitleaks
rev: v8.21.2
hooks:
- id: gitleaks