Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD across contents and paths, upstream package/repo coordinates -> @golem15/msd-core and golem15com/msd-core. Deep links into upstream history, sibling upstream packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is. Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line, package/plugin identity, regenerated lockfile, install-tree fixtures, derived registries and benchmark baseline; migration checksum baseline re-locked (MSD keeps its own install state, so no install had applied the old sums); sort-order and regex-escaped expectations in tests adjusted.
33 lines
2.0 KiB
Plaintext
33 lines
2.0 KiB
Plaintext
# .secretscanignore — Files to exclude from secret scanning
|
|
#
|
|
# Glob patterns (one per line) for files that should be skipped.
|
|
# Comments (#) and empty lines are ignored.
|
|
#
|
|
# ANNOTATION FORMAT (required for --strict compliance):
|
|
# # allow: <pattern> reason="..." owner="..." expires="YYYY-MM-DD" [rule-id="..."]
|
|
# <pattern>
|
|
#
|
|
# Required keys : reason, owner, expires
|
|
# Optional keys : rule-id (REQUIRED when pattern contains * wildcards)
|
|
#
|
|
# Grandfathered entries (plain comment, no structured annotation) are accepted
|
|
# in default mode with a deprecation warning, but fail under --strict mode.
|
|
# --strict is used for release and security-review CI lanes.
|
|
#
|
|
# Governance references:
|
|
# - GitGuardian exclusion annotation convention:
|
|
# https://docs.gitguardian.com/internal-repositories-monitoring/integrations/cli/secrets
|
|
# - CNCF Security TAG threat-model exception lifecycle:
|
|
# https://github.com/cncf/tag-security/blob/main/community/working-groups/threat-modeling/templates/threats.md
|
|
#
|
|
# Lint: scripts/secret-scan-lint.sh --file .secretscanignore
|
|
# Strict scan: scripts/secret-scan.sh --diff origin/main --strict
|
|
|
|
# allow: msd-core/workflows/plan-phase.md reason="contains illustrative DATABASE_URL/REDIS_URL example strings used as documentation placeholders — not real credentials" owner="@open-gsd/maintainers" expires="2027-06-30"
|
|
msd-core/workflows/plan-phase.md
|
|
|
|
# allow: msd-core/references/verification-patterns.md reason="documents stub/placeholder RED-FLAG examples for env vars (illustrative Stripe test-key, database-URL and API-key placeholders shown as what NOT to ship) — not real credentials" owner="@open-gsd/maintainers" expires="2027-06-30"
|
|
msd-core/references/verification-patterns.md
|
|
# allow: docs/zh-CN/references/verification-patterns.md reason="translated copy of the English verification-patterns.md — carries the same illustrative placeholder examples (Stripe test-key, database-URL, API-key) as what NOT to ship" owner="@open-gsd/maintainers" expires="2027-06-30"
|
|
docs/zh-CN/references/verification-patterns.md
|