-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy path.gitleaksignore
More file actions
55 lines (46 loc) · 2.73 KB
/
Copy path.gitleaksignore
File metadata and controls
55 lines (46 loc) · 2.73 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
# Gitleaks ignore file for wildfire_mvp_v3
# Only includes FINGERPRINTS of specific findings that should be ignored
# (e.g., references to OLD rotated keys in security documentation)
#
# NOTE: This file uses fingerprints (finding IDs), NOT path patterns
# For path-based ignoring (build artifacts, etc.), use .gitleaks.toml
# Android build.gradle.kts - Old key from initial commit (rotated 2025-10-20)
android/app/build.gradle.kts:gcp-api-key:37
# iOS AppDelegate.swift - Old key from initial commit (rotated 2025-10-19)
ios/Runner/AppDelegate.swift:gcp-api-key:14
# Security notice documentation - References to old rotated keys (documentation only)
docs/SECURITY_NOTICE.md:gcp-api-key:5
docs/SECURITY_NOTICE.md:gcp-api-key:25
# API Key Rotation Guide - Documents which keys need rotation (not real usage)
docs/API_KEY_ROTATION_GUIDE.md:gcp-api-key:6
docs/API_KEY_ROTATION_GUIDE.md:gcp-api-key:7
docs/API_KEY_ROTATION_GUIDE.md:gcp-api-key:102
docs/API_KEY_ROTATION_GUIDE.md:gcp-api-key:103
docs/history/deprecated/API_KEY_ROTATION_GUIDE.md:gcp-api-key:6
docs/history/deprecated/API_KEY_ROTATION_GUIDE.md:gcp-api-key:7
docs/history/deprecated/API_KEY_ROTATION_GUIDE.md:gcp-api-key:102
docs/history/deprecated/API_KEY_ROTATION_GUIDE.md:gcp-api-key:103
# Security documentation with "REDACTED" placeholders in examples (not real keys)
docs/SECURITY_AUDIT_REPORT_2025-10-29.md:gcp-api-key:23
docs/SECURITY_AUDIT_REPORT_2025-10-29.md:gcp-api-key:24
docs/SECURITY_AUDIT_REPORT_2025-10-29.md:gcp-api-key:25
docs/SECURITY_INCIDENT_RESPONSE_2025-10-29.md:gcp-api-key:29
docs/SECURITY_INCIDENT_RESPONSE_2025-10-29.md:gcp-api-key:67
docs/SECURITY_DOCUMENTATION_GUIDELINES.md:gcp-api-key:9
docs/PREVENT_API_KEY_LEAKS.md:generic-api-key:237
docs/PREVENT_API_KEY_LEAKS.md:generic-api-key:253
docs/PREVENT_API_KEY_LEAKS.md:gcp-api-key:138
docs/history/deprecated/PREVENT_API_KEY_LEAKS.md:generic-api-key:237
docs/history/deprecated/PREVENT_API_KEY_LEAKS.md:generic-api-key:253
.github/copilot-instructions.md:gcp-api-key:1119
.github/copilot-instructions.md:gcp-api-key:1133
# Test files with mock/example API keys (not real secrets)
test/scripts/build_web_ci_test.sh:generic-api-key:65
test/scripts/build_web_ci_test.sh:generic-api-key:103
specs/012-a11-ci-cd/contracts/build-script-contract.sh:generic-api-key:199
# NOTE: All documentation files now use safe placeholders (YOUR_API_KEY_HERE, YOUR_WEB_API_KEY_HERE)
# "REDACTED" strings in security documentation are intentional examples showing what was exposed
#
# Test examples in documentation use inline gitleaks:allow comments (best practice)
# RiskBanner specification - False positive on Flutter constant naming (kBannerPadding=16.0)
cd2452759d5423fc6e0370099fa5602ebc69f1e1:specs/016-016-a14-riskbanner/PROGRESS_REPORT.md:generic-api-key:12