Summary
An AWS secret access key is 40 characters from [A-Za-z0-9/+=]. The custom pattern scripts/setup-git-secrets.sh registers for it is the negated class [^A-Za-z0-9/+=]{40}[^A-Za-z0-9/+=], so it matches 41 consecutive characters that are not key characters. Tested with grep -E, it matched only a run of U+2501 box-drawing characters (the separator lines this repo's own scripts print) and never a synthetic 40-character base64 key. Severity is medium rather than high because git secrets --register-aws on line 43 and the assignment-shaped pattern on line 53 still block secret_key = "<40 chars>"; only a bare, unassigned key slips through the local gate.
Location
scripts/setup-git-secrets.sh:52 at 3c0f8ac94048a2c36fce5ccddee54e6c4849a5cd
Failure scenario
A 40-character secret key committed on its own line (a pasted credential, a YAML value without quotes) is not matched by this pattern at all. The comment beside it claims AWS-secret coverage the gate does not provide, and every developer's local pre-commit hook inherits the dead pattern via make setup-git-secrets.
Evidence
git secrets --add '[^A-Za-z0-9/+=]{40}[^A-Za-z0-9/+=]' # AWS Secret Access Key
Suggested fix
Replace with a positive class anchored on non-key boundaries, for example (^|[^A-Za-z0-9/+=])[A-Za-z0-9/+=]{40}([^A-Za-z0-9/+=]|$), and add a fixture proving it fires on a synthetic 40-character key. Worth fixing together with the allowed-pattern defect in the same script (audit finding A14-010).
Found by the 2026-09-02 codebase audit, finding A14-009, reported by one reviewer and independently confirmed by a second. Full report: docs/audits/codebase-audit-2026-09-02.md.
Summary
An AWS secret access key is 40 characters from
[A-Za-z0-9/+=]. The custom patternscripts/setup-git-secrets.shregisters for it is the negated class[^A-Za-z0-9/+=]{40}[^A-Za-z0-9/+=], so it matches 41 consecutive characters that are not key characters. Tested withgrep -E, it matched only a run of U+2501 box-drawing characters (the separator lines this repo's own scripts print) and never a synthetic 40-character base64 key. Severity is medium rather than high becausegit secrets --register-awson line 43 and the assignment-shaped pattern on line 53 still blocksecret_key = "<40 chars>"; only a bare, unassigned key slips through the local gate.Location
scripts/setup-git-secrets.sh:52at 3c0f8ac94048a2c36fce5ccddee54e6c4849a5cdFailure scenario
A 40-character secret key committed on its own line (a pasted credential, a YAML value without quotes) is not matched by this pattern at all. The comment beside it claims AWS-secret coverage the gate does not provide, and every developer's local pre-commit hook inherits the dead pattern via
make setup-git-secrets.Evidence
Suggested fix
Replace with a positive class anchored on non-key boundaries, for example
(^|[^A-Za-z0-9/+=])[A-Za-z0-9/+=]{40}([^A-Za-z0-9/+=]|$), and add a fixture proving it fires on a synthetic 40-character key. Worth fixing together with the allowed-pattern defect in the same script (audit finding A14-010).Found by the 2026-09-02 codebase audit, finding
A14-009, reported by one reviewer and independently confirmed by a second. Full report:docs/audits/codebase-audit-2026-09-02.md.