From 22f4a905bbee1502c89d03d3fd8ae9c5335408e0 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 15:43:01 +0100 Subject: [PATCH] =?UTF-8?q?fix(gitleaks):=20estate=20baseline=20=E2=80=94?= =?UTF-8?q?=20a=20documentation=20filename=20is=20not=20a=20secret?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Add one anchored VALUE entry to config/gitleaks/estate-baseline.toml: ^[A-Za-z0-9][A-Za-z0-9._-]*\.(adoc|md)$ generic-api-key keys on an `auth`-like word in a prose record's key and captures the doc filename in its quoted value as the "secret". Found in echo-types (.machine_readable/6a2 STATE record), where it has red `scan / gitleaks` on main since 2026-09-27 and on PR #331 (echo-types#329). echo-types has no .gitleaks.toml, so the secret-scanner reusable fetches this baseline from standards `ref: main` and the cure reaches it on its next run. Measured on the CI-pinned gitleaks 8.18.4 (tarball sha256 verified): mutant baseline without the entry, echo-types tree 1 finding cure baseline with the entry, echo-types tree 0 findings control fixture: a real-looking token beside a filename record — without the entry lines 1,2 flagged; with it, line 1 only standards own tree (.gitleaks.toml extends the baseline): 0 before, 0 after Config and reports kept outside --source (the instrument trap in the header). Estate-wide admission: no credential format ends in .adoc or .md and the class admits no `/`, so it names one file, never a path or a blob. The comment describes the shape rather than quoting the triggering line. Ratchet-exception: config/gitleaks/estate-baseline.toml — one anchored value entry (doc filename), owner-ruled 2026-09-30 as the echo-types #331 cure; see commit body for mutant/cure/control Refs: hyperpolymath/echo-types#329, hyperpolymath/echo-types#331 Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57 --- config/gitleaks/estate-baseline.toml | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/config/gitleaks/estate-baseline.toml b/config/gitleaks/estate-baseline.toml index f6d872a49..a7381fb97 100644 --- a/config/gitleaks/estate-baseline.toml +++ b/config/gitleaks/estate-baseline.toml @@ -211,4 +211,15 @@ regexes = [ # Haskell declaration `data Ed25519KeyPair = Ed25519KeyPair`. A bare # CamelCase identifier with no digits or separators is a type, not a key. '''^(Ed25519|X25519|Curve25519|RSA|ECDSA|EdDSA|Secp256k1)[A-Za-z]*$''', + + # --- document references ------------------------------------------------- + # A single documentation FILENAME captured as a record's value. Shape (kept + # described, not shown, per the rule at the top of this list): a prose record + # whose KEY contains an `auth`-like keyword (e.g. an "authoritative text" + # field) and whose quoted VALUE starts with a doc filename, so + # `generic-api-key` captures the filename as the secret. Found in a + # machine-readable STATE record, echo-types#329 (PR #331), 2026-09-30. + # True for every repository: no credential format ends in `.adoc` or `.md`, + # and the class admits no `/`, so it names one file, never a path or a blob. + '''^[A-Za-z0-9][A-Za-z0-9._-]*\.(adoc|md)$''', ]