[extend] useDefault = true [allowlist] description = "Test fixtures, example configs, and instructional skill docs" paths = [ # Anchored to a real ``tests/`` path segment so it can't allowlist an # unrelated path that merely contains the substring "tests". '''(^|/)tests/''', '''\.env\.example$''', '''README\.md$''', # Persona/library skill files are instructional Markdown that contain # illustrative (placeholder) credentials by design — not real secrets. This # is intentionally broad; do not paste real secrets into persona docs. '''^personas/.*\.md$''', # Backup archives bundled by the HF Learn cron — not real secrets. '''\.curator_backups/''', ] regexes = [ # Documentation placeholders like `sk-xxxxxxxxxxxxxxxx`. '''sk-x{8,}''', # Skill-bundle integrity hash (`github-auth:` in `.bundled_manifest`) — # a content digest, not a credential, so allowlisting it hides nothing secret. '''2a2ad52aedb7cb9019df9cab263845f0''', # # NOTE: the previously allowlisted `ck_…` consumer key and # `H9hhwS50qwxJIORLdXbIgFHMUeMKyn4h` token were removed here on purpose. They # look like real credentials that were scrubbed from the working tree but # remain in git history. Value-allowlisting them only hid them from the # scanner — it did NOT invalidate them. They must be ROTATED/REVOKED at their # providers (see docs/security-hardening.md). Removing the allowlist lets # gitleaks flag them if they are ever reintroduced into a commit. ]