chore(16-04): add gitleaks config with fixture + env allowlists
- Add .gitleaks.toml inheriting default ruleset via [extend] useDefault = true - Allowlist apps/api/tests/fixtures/vapid.ts (test-only VAPID keypair) - Allowlist .env.example (intentional placeholder template) - Allowlist apps/api/.env.spike (dev/spike values)
This commit is contained in:
@@ -0,0 +1,20 @@
|
||||
# .gitleaks.toml — gitleaks configuration
|
||||
# Repo: familysync
|
||||
|
||||
title = "FamilySync gitleaks config"
|
||||
|
||||
[extend]
|
||||
# Extend with the default ruleset (all standard secret patterns)
|
||||
useDefault = true
|
||||
|
||||
[[allowlists]]
|
||||
description = "Test fixture VAPID keys — documented test-only values, not production keys"
|
||||
paths = ['''apps/api/tests/fixtures/vapid\.ts''']
|
||||
|
||||
[[allowlists]]
|
||||
description = ".env.example — intentional placeholder/template values, not live secrets"
|
||||
paths = ['''\.env\.example$''']
|
||||
|
||||
[[allowlists]]
|
||||
description = "apps/api/.env.spike — dev/spike values, not production secrets"
|
||||
paths = ['''apps/api/\.env\.spike$''']
|
||||
Reference in New Issue
Block a user