secret-guard: triaged allow list (fakes by hash, test PEMs by path)
Private-key matches are only the BEGIN line (same hash everywhere), so they are allowed by path+kind; everything else by hash. Real revoked tokens (1354fc9b, d49dc2ba) are pinned by a test to never be allowed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,5 +1,46 @@
|
||||
# Secret guard allow-list: KNOWN FAKE values that look like secrets (test
|
||||
# fixtures, docs). Allowed BY HASH (sha256[:8] of the value), never by path, so a
|
||||
# real secret in the same file still flags. Every entry MUST say why.
|
||||
# Owner: Windy Git lane (13); changes go through the orchestrator.
|
||||
allow: []
|
||||
# fixtures, docs). Allowed BY HASH (sha256[:8] of the value), so a real secret
|
||||
# in the same file still flags. Private-key blocks (the match is only the BEGIN
|
||||
# line, same hash everywhere) are allowed by PATH + kind instead.
|
||||
# Every entry MUST say why. Owner: Windy Git lane (13); changes via the orchestrator.
|
||||
# Triage 09-24 (values never printed): each hash checked against every version of
|
||||
# the lockbox; fakes judged by impossible length for the kind (real Anthropic keys
|
||||
# ~108 chars, OpenAI 51 or 160+), fake-words, or identity with upstream public
|
||||
# fixtures. NOT allowed, remove instead: 1354fc9b (old @Windy_0_bot token) and
|
||||
# d49dc2ba (old Anthropic key), both real and revoked, in public windy-agent.
|
||||
allow:
|
||||
- repo: windy-code
|
||||
hashes: [ac9265e5, 46eb1235]
|
||||
reason: "Upstream microsoft/vscode terminalEnvironment.test.ts fixtures (identical hash upstream; public)."
|
||||
- repo: windy-code
|
||||
paths: ["build/azure-pipelines/common/publish.ts"]
|
||||
kinds: [private key block]
|
||||
reason: "Upstream VS Code build script (PEM header string in code, not a key)."
|
||||
- repo: windy-agent
|
||||
hashes: [a9235a6d, dd6a2baa, 02c362d8, a6f6ff79, f7503b21, d0c94833, 4ab092e3, e3aa1eb8, 833382ee]
|
||||
reason: "Redaction/sanitizer test fixtures; lengths impossible for real Anthropic/OpenAI keys; never in the lockbox."
|
||||
- repo: windy-agent
|
||||
paths: ["tests/test_agent_keys.py"]
|
||||
kinds: [private key block]
|
||||
reason: "Test-generated key material for agent-key tests."
|
||||
- repo: windy-mind
|
||||
hashes: [f8a630b2]
|
||||
reason: "Provider test fixture (27 chars; a real Anthropic key is ~108)."
|
||||
- repo: windy-pro
|
||||
hashes: [756de8d8, 7828319d, 1a5d44a2]
|
||||
reason: ".env.production.example placeholder + crash-summary test fixtures (AWS doc EXAMPLE key shape, short fake Slack token)."
|
||||
- repo: windy-pro
|
||||
paths: ["account-server/docs/oauth-providers.md"]
|
||||
kinds: [private key block]
|
||||
reason: "Docs show the PEM header format; no key material."
|
||||
- repo: windytalk
|
||||
hashes: [baf8656a]
|
||||
reason: "Diagnostics redaction test fixture (fake-word in value)."
|
||||
- repo: eternitas
|
||||
paths: ["tests/golden_vectors/**", "tests/test_soul_vault_key_separation.py"]
|
||||
kinds: [private key block]
|
||||
reason: "Test vectors and throwaway keys for signature/vault tests."
|
||||
- repo: windy-drops
|
||||
paths: ["tools/conformance/test-keys/*"]
|
||||
kinds: [private key block]
|
||||
reason: "Conformance-suite test keys (named test-private.pem)."
|
||||
|
||||
Reference in New Issue
Block a user