Files
msd-core/.secretscanignore
Jakub Zych a9a7a328e6 refactor: hard-fork GSD -> MSD (Make Software Done)
Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD
across contents and paths, upstream package/repo coordinates -> @golem15/msd-core
and golem15com/msd-core. Deep links into upstream history, sibling upstream
packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is.

Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line,
package/plugin identity, regenerated lockfile, install-tree fixtures, derived
registries and benchmark baseline; migration checksum baseline re-locked
(MSD keeps its own install state, so no install had applied the old sums);
sort-order and regex-escaped expectations in tests adjusted.
2026-10-06 01:47:40 +02:00

33 lines
2.0 KiB
Plaintext

# .secretscanignore — Files to exclude from secret scanning
#
# Glob patterns (one per line) for files that should be skipped.
# Comments (#) and empty lines are ignored.
#
# ANNOTATION FORMAT (required for --strict compliance):
# # allow: <pattern> reason="..." owner="..." expires="YYYY-MM-DD" [rule-id="..."]
# <pattern>
#
# Required keys : reason, owner, expires
# Optional keys : rule-id (REQUIRED when pattern contains * wildcards)
#
# Grandfathered entries (plain comment, no structured annotation) are accepted
# in default mode with a deprecation warning, but fail under --strict mode.
# --strict is used for release and security-review CI lanes.
#
# Governance references:
# - GitGuardian exclusion annotation convention:
# https://docs.gitguardian.com/internal-repositories-monitoring/integrations/cli/secrets
# - CNCF Security TAG threat-model exception lifecycle:
# https://github.com/cncf/tag-security/blob/main/community/working-groups/threat-modeling/templates/threats.md
#
# Lint: scripts/secret-scan-lint.sh --file .secretscanignore
# Strict scan: scripts/secret-scan.sh --diff origin/main --strict
# allow: msd-core/workflows/plan-phase.md reason="contains illustrative DATABASE_URL/REDIS_URL example strings used as documentation placeholders — not real credentials" owner="@open-gsd/maintainers" expires="2027-06-30"
msd-core/workflows/plan-phase.md
# allow: msd-core/references/verification-patterns.md reason="documents stub/placeholder RED-FLAG examples for env vars (illustrative Stripe test-key, database-URL and API-key placeholders shown as what NOT to ship) — not real credentials" owner="@open-gsd/maintainers" expires="2027-06-30"
msd-core/references/verification-patterns.md
# allow: docs/zh-CN/references/verification-patterns.md reason="translated copy of the English verification-patterns.md — carries the same illustrative placeholder examples (Stripe test-key, database-URL, API-key) as what NOT to ship" owner="@open-gsd/maintainers" expires="2027-06-30"
docs/zh-CN/references/verification-patterns.md