Skip to content

ci(security): lefthook + gitleaks secret gate - #535

Open
gHashTag wants to merge 2 commits into
devfrom
security/secret-gate
Open

gHashTag wants to merge 2 commits into
devfrom
security/secret-gate

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 5, 2026

Copy link
Copy Markdown
Owner

No issue to close: issues are disabled on gHashTag/BrowserOS.

What changed

  • .gitleaks.toml: the shared gHashTag rules (canonical copy in gHashTag/t27 PR #6433, including hardcoded-password-literal), plus narrow allowlists for the verified non-secrets on dev.
  • lefthook.yml: the existing config is extended, not replaced. A secret-gate command is added to pre-commit (staged changes) and pre-push (commits not yet on a remote).
  • .github/workflows/secret-scan.yml: the CI twin. It scans the PR or push range, so --no-verify cannot bypass it.
  • README.md: a "Secrets never enter the repository" section.

Triage of the 413 findings on dev. All are false positives:

  • 408: packages/browseros-agent/apps/eval/data/webbench/browserusefinal.csv, a third-party WebBench eval dataset. The task prompts include benchmark test-site logins (path allowlist for that data dir's CSVs).
  • 2: kSentryMinidumpUrl in two chromium patches. This is a Sentry client DSN key, which is public by design and ships in the binary (line allowlist).
  • 1: apps/agent/wxt.config.ts, the Chrome extension manifest public key that pins the extension ID (path AND line allowlist).
  • 1: bun.lock, the npm package name @inquirer/password (line allowlist).
  • 1: packages/shared/tests/smoke.test.ts, a test fixture string (line allowlist).

Verified

  • gitleaks dir . --config .gitleaks.toml exits 0.
  • A staged probe containing a hardcoded wifi_password literal makes gitleaks git --staged --config .gitleaks.toml . exit 1.
  • lefthook install --force exits 0. core.hooksPath is set locally, so plain install refuses. This commit went through the pre-commit secret-gate, and the push went through the pre-push secret-gate.

Credentials to rotate

None. No hardcoded credentials of ours were found.

馃 Generated with Claude Code

Add .gitleaks.toml with the shared gHashTag rules (canonical copy in
gHashTag/t27 PR #6433) plus narrow allowlists for the verified
non-secrets on dev: the third-party WebBench eval CSVs, the public
Sentry minidump DSN key, the extension manifest public key, an npm
package name in bun.lock and one test fixture string.

Wire gitleaks into the existing lefthook pre-commit and pre-push, add
the CI twin (secret-scan workflow), and document the rule in README.
Issues are disabled on this repository, so there is no issue to close.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions github-actions Bot added the CI/CD label Oct 5, 2026
gitleaks 8.30 applies a global [[allowlists]] block that has paths and
condition = "AND" to the whole file: a planted wifi_password line in a
matching path was not reported. Drop paths from those blocks and keep
exact line regexes only. Verified: full scan exits 0, a probe line in
each formerly allowlisted file now exits 1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant