feat(security): Add gitleaks secret scanning to prevent API key leaks

After a real API key leaked through test files with realistic hex patterns,
this adds automated secret detection: .gitleaks.toml with custom rules for
OpenRouter/OpenAI/Anthropic/Google keys, and .pre-commit-config.yaml wiring
gitleaks as a pre-commit hook. Test keys locally updated to use FAKE-/NOTREAL
conventions that pass the allowlist.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
AIOSAI
2026-04-10 04:16:50 -07:00
co-authored by Claude Opus 4.6
parent aba5cc32bd
commit fc2e9daccc
2 changed files with 77 additions and 0 deletions
+10
View File
@@ -0,0 +1,10 @@
# Pre-commit hooks for AIPass
# Install: pip install pre-commit && pre-commit install
# Manual run: pre-commit run --all-files
repos:
# Gitleaks — secret detection
- repo: https://github.com/gitleaks/gitleaks
rev: v8.21.2
hooks:
- id: gitleaks