From df7696e1813553a3934de08ef4879125df5c66e6 Mon Sep 17 00:00:00 2001 From: Larry Klosowski Date: Sun, 27 Sep 2026 11:34:40 -0700 Subject: [PATCH] ci(secret-scan): allowlist public contract addresses in the generated address book The merge-gate secret-scan (gitleaks) flags the generated on-chain address book as a false positive. The default generic-api-key rule keys off trigger words in the contract NAME -- e.g. "ModelAccessControl" (the word "Access") and "WebAuthnP256Validator" (the word "Auth") -- and reports their values: "ModelAccessControl": "0x...40 hex..." Those values are PUBLIC 40204 contract addresses (0x + 40 hex = 20 bytes), not credentials. Nothing secret is exposed. Fix: add a NARROW .gitleaks.toml allowlist that exempts ONLY findings whose secret is exactly a 0x-prefixed 40-hex EVM address. It keeps useDefault = true, disables no rule, and skips no file. Narrowness proven locally with gitleaks 8.30.1 (the version pinned by .github/workflows/merge-gate.yml): after temporarily injecting a Stripe key, a GitHub PAT, a 0x-prefixed 64-hex private key, and a generic api_key into crates/chainio/src/generated/addresses.json, gitleaks still reports all four (leaks found: 4) while the public addresses are exempt. The test edit was not committed. A paths-scoped allowlist was deliberately avoided: in gitleaks 8.30.1 an allowlist paths match skips the whole file even with condition="AND", which would suppress real secrets in that file. Scoping by the address value pattern is strictly narrower. Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_01Vv2gVzy5XLFKg48yckN9YQ --- .gitleaks.toml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 .gitleaks.toml diff --git a/.gitleaks.toml b/.gitleaks.toml new file mode 100644 index 0000000..6bbf9ea --- /dev/null +++ b/.gitleaks.toml @@ -0,0 +1,26 @@ +# gitleaks configuration — narrow secret-scan allowlist (hardening / scanner compat) +# +# The default "generic-api-key" rule flags entries in the GENERATED on-chain +# address book whose contract NAME contains a trigger word such as "Access" or +# "Auth" — e.g. "ModelAccessControl": "0x...", "WebAuthnP256Validator": "0x...". +# The flagged value is a PUBLIC 40204 contract address (0x + 40 hex = 20 bytes), +# not a credential. Nothing secret. +# +# This allowlist exempts ONLY findings whose SECRET is exactly a 0x-prefixed +# 40-hex EVM address. It does NOT disable any rule and does NOT skip any file: +# real credentials (Stripe/GitHub/AWS keys, 64-hex private keys, JWTs, ...) are +# still caught, because none of them are a bare 20-byte hex address. +# +# NOTE: a `paths`-scoped allowlist was deliberately avoided. In gitleaks 8.30.1 +# (the version pinned by .github/workflows/merge-gate.yml) an allowlist `paths` +# match skips the WHOLE file even with condition="AND", which would suppress +# real secrets living in that file. Scoping by the address VALUE pattern is +# strictly narrower and was verified with an injection test (see PR body). + +[extend] +useDefault = true + +[[allowlists]] +description = "Public 40204 contract addresses (0x + 40 hex) in the generated address book are not secrets" +regexes = ['''^0x[0-9a-fA-F]{40}$'''] +regexTarget = "secret"