-
Notifications
You must be signed in to change notification settings - Fork 2.6k
Expand file tree
/
Copy pathgeneric_config_secrets.yml
More file actions
47 lines (47 loc) · 1.11 KB
/
Copy pathgeneric_config_secrets.yml
File metadata and controls
47 lines (47 loc) · 1.11 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
detectors:
- name: generic-config-secret
keywords:
- secret
- password
- passwd
- pwd
- apikey
- api_key
- api-key
- token
- credential
- cred
- auth
regex:
secret: |-
(?i)[\w.-]{0,50}?(?:secret|passw(?:or)?d|pwd|api[_-]?key|token|credentials?|creds?|auth)[\w.-]{0,20}\s*[=:]\s*["'`]?([^\s"'`,;]{6,150})["'`]?\s*(?:$|[\r\n#;])
entropy: 2.5
# Applied to the captured value only (not the key), so a key path like
# `env.password` or `app.env.secret` doesn't cause a real hardcoded
# secret to be excluded just because "env" appears in the key.
exclude_regexes_capture:
- '(?i)^\$\{[^}]*\}$'
- '(?i)^\{\{[^}]*\}\}$'
- '(?i)^%[A-Z_]+%$'
- '(?i)^\$[A-Z_][A-Z0-9_]*$'
- '(?i)^(?:process\.env\.|os\.environ|getenv\(|System\.getenv\()'
- '(?i)^(?:vault|kms|secretsmanager|parameterstore)://'
exclude_words:
- "changeme"
- "change_me"
- "change-me"
- "changethis"
- "xxxxxx"
- "example"
- "placeholder"
- "dummy"
- "redacted"
- "your_api_key"
- "your-api-key"
- "yourapikey"
- "insert_secret_here"
- "todo"
- "fixme"
- "null"
- "none"
- "false"