title = "gitleaks config for Lotus Chat (cinny fork)" # Gitea #95 — secret scanning was entirely absent. Extend gitleaks' built-in # ruleset (don't replace it) and allowlist the known-public infrastructure # URLs that show up in tracked config, which are hostnames, not secrets. [extend] useDefault = true [allowlist] description = "Known-public Lotus/Matrix homeserver + npm registry URLs — not secrets" regexes = [ '''https?://matrix\.lotusguild\.org''', '''https?://code\.lotusguild\.org/api/packages/LotusGuild/npm/''', '''matrix\.lotusguild\.org''', ] paths = [ '''config\.json''', '''\.npmrc''', # Build output and vendored bundles are not source — CI scans a fresh # checkout, but a local run after `npm run build` would trip on minified # matrix-js-sdk crypto identifiers (claimedEd25519Key etc.). '''^dist/''', '''^node_modules/''', '''^public/element-call/''', ] # localStorage / IndexedDB key NAMES (e.g. `STORAGE_KEY = 'cinny_recent_gifs_v1'`) # match generic-api-key purely because the variable is called *_KEY. They are # namespaced identifiers, not credentials. [[rules]] id = "generic-api-key" [rules.allowlist] regexTarget = "line" regexes = [ '''(STORAGE|CACHE|IDB|DB|LS)_KEY\s*=\s*['"](cinny|lotus)[-_][a-z0-9_-]+['"]''', ]