Files
windy-git/ci/secret-guard-allow.yml
Kit OC5 d28da26000
All checks were successful
check / gate (push) Successful in 22s
secret-guard: no live credentials in bridged repos (hash-only findings)
New guard windy-git/secret-guard (warn-only) over EVERY text file: Telegram,
GitHub, AWS, Slack, Anthropic, OpenAI, Stripe live, Google API keys and
private-key blocks (scripts/secret_shapes.py, shared with the weekly public
scan). A finding carries "<kind> #<sha256[:8]>", never the value (house rule
10). Known fakes allowed BY HASH (ci/secret-guard-allow.yml). GUARDS_STATUS
gets a secrets column. Leak hunt 09-24: @Windy_0_bot token in a public fixture.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-24 03:01:59 -04:00

6 lines
303 B
YAML

# Secret guard allow-list: KNOWN FAKE values that look like secrets (test
# fixtures, docs). Allowed BY HASH (sha256[:8] of the value), never by path, so a
# real secret in the same file still flags. Every entry MUST say why.
# Owner: Windy Git lane (13); changes go through the orchestrator.
allow: []