# Secret guard allow-list: KNOWN FAKE values that look like secrets (test # fixtures, docs). Allowed BY HASH (sha256[:8] of the value), never by path, so a # real secret in the same file still flags. Every entry MUST say why. # Owner: Windy Git lane (13); changes go through the orchestrator. allow: []