diff --git a/config/gitleaks/estate-baseline.toml b/config/gitleaks/estate-baseline.toml index f6d872a49..a7381fb97 100644 --- a/config/gitleaks/estate-baseline.toml +++ b/config/gitleaks/estate-baseline.toml @@ -211,4 +211,15 @@ regexes = [ # Haskell declaration `data Ed25519KeyPair = Ed25519KeyPair`. A bare # CamelCase identifier with no digits or separators is a type, not a key. '''^(Ed25519|X25519|Curve25519|RSA|ECDSA|EdDSA|Secp256k1)[A-Za-z]*$''', + + # --- document references ------------------------------------------------- + # A single documentation FILENAME captured as a record's value. Shape (kept + # described, not shown, per the rule at the top of this list): a prose record + # whose KEY contains an `auth`-like keyword (e.g. an "authoritative text" + # field) and whose quoted VALUE starts with a doc filename, so + # `generic-api-key` captures the filename as the secret. Found in a + # machine-readable STATE record, echo-types#329 (PR #331), 2026-09-30. + # True for every repository: no credential format ends in `.adoc` or `.md`, + # and the class admits no `/`, so it names one file, never a path or a blob. + '''^[A-Za-z0-9][A-Za-z0-9._-]*\.(adoc|md)$''', ]