feat(security): Add gitleaks secret scanning to prevent API key leaks
After a real API key leaked through test files with realistic hex patterns, this adds automated secret detection: .gitleaks.toml with custom rules for OpenRouter/OpenAI/Anthropic/Google keys, and .pre-commit-config.yaml wiring gitleaks as a pre-commit hook. Test keys locally updated to use FAKE-/NOTREAL conventions that pass the allowlist. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
aba5cc32bd
commit
fc2e9daccc
@@ -0,0 +1,10 @@
|
||||
# Pre-commit hooks for AIPass
|
||||
# Install: pip install pre-commit && pre-commit install
|
||||
# Manual run: pre-commit run --all-files
|
||||
|
||||
repos:
|
||||
# Gitleaks — secret detection
|
||||
- repo: https://github.com/gitleaks/gitleaks
|
||||
rev: v8.21.2
|
||||
hooks:
|
||||
- id: gitleaks
|
||||
Reference in New Issue
Block a user