From 53fbcfe78fadd4f4731c5d3397200d9259c723ae Mon Sep 17 00:00:00 2001 From: Kit OC5 Date: Thu, 1 Oct 2026 00:59:59 -0400 Subject: [PATCH] secret-guard allow: windy-code VS Code public aiKey, windytalk redaction fixture (hash not in lockbox) Co-Authored-By: Claude Sonnet 5.5 --- ci/secret-guard-allow.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/ci/secret-guard-allow.yml b/ci/secret-guard-allow.yml index 1059f58..096a99a 100644 --- a/ci/secret-guard-allow.yml +++ b/ci/secret-guard-allow.yml @@ -51,3 +51,9 @@ allow: paths: ["api/tests/test_secret_guard.py"] kinds: [private key block] reason: "The guard's own test uses a PEM header string as a sample." + - repo: windy-code + hashes: ["23f32607"] + reason: "VS Code OSS extensions' package.json aiKey: Microsoft's public telemetry (App Insights) key, shipped in every VS Code build; not a Windy credential." + - repo: windytalk + hashes: ["c4189d79"] + reason: "apps/desktop/test/diagnostics.test.ts redaction fixture (hexSecret beside a fake sk-ant token); hash checked against the lockbox 10-01: not present."