diff --git a/.gitleaks.toml b/.gitleaks.toml new file mode 100644 index 0000000..9002d0d --- /dev/null +++ b/.gitleaks.toml @@ -0,0 +1,12 @@ +# Extends the default gitleaks rules and allows one thing only: the fake +# placeholder YOUR_API_KEY used in a sample curl command. It is not a credential. +# Matching on the placeholder text (not a commit hash) keeps it working +# after squash merges, which create new commit hashes. +title = "context-engineering-toolkit" + +[extend] +useDefault = true + +[allowlist] +description = "Placeholder API key in documentation examples" +regexes = ['''YOUR_API_KEY'''] diff --git a/.gitleaksignore b/.gitleaksignore deleted file mode 100644 index a31d15e..0000000 --- a/.gitleaksignore +++ /dev/null @@ -1,3 +0,0 @@ -# Placeholder token in a sample curl command (Authorization: Bearer YOUR_API_KEY), docs-pipeline sample doc. -# It is a fake value in a made-up example, not a credential. The line sits in an earlier commit of PR 30, which cannot be rewritten. -445b46ad65f98f2e34928eaf9340d5417edcde79:pipelines/docs-pipeline/sample/acme-orders-cancellations.md:curl-auth-header:22