Files
msd-core/.secretscanignore
Tom Boucher fee72d5560 fix(#3044): add zh-CN verification-patterns.md to secret-scan exclusions (#3122)
* fix(#3044): add zh-CN verification-patterns.md to secret-scan exclusions

The translated document carries the same illustrative placeholder examples
(Stripe test-key, database-URL, API-key) as the English source, which is
already excluded. The exclusion was never extended to the zh-CN translation,
causing the strict-mode scan to fail. No other locale has a translation of
this file (verified: ja-JP, ko-KR, pt-BR do not have it).

* chore(#3044): backfill changeset PR number 3122

---------

Co-authored-by: sim <sim@local>
2026-08-06 11:34:31 -04:00

33 lines
2.0 KiB
Plaintext

# .secretscanignore — Files to exclude from secret scanning
#
# Glob patterns (one per line) for files that should be skipped.
# Comments (#) and empty lines are ignored.
#
# ANNOTATION FORMAT (required for --strict compliance):
# # allow: <pattern> reason="..." owner="..." expires="YYYY-MM-DD" [rule-id="..."]
# <pattern>
#
# Required keys : reason, owner, expires
# Optional keys : rule-id (REQUIRED when pattern contains * wildcards)
#
# Grandfathered entries (plain comment, no structured annotation) are accepted
# in default mode with a deprecation warning, but fail under --strict mode.
# --strict is used for release and security-review CI lanes.
#
# Governance references:
# - GitGuardian exclusion annotation convention:
# https://docs.gitguardian.com/internal-repositories-monitoring/integrations/cli/secrets
# - CNCF Security TAG threat-model exception lifecycle:
# https://github.com/cncf/tag-security/blob/main/community/working-groups/threat-modeling/templates/threats.md
#
# Lint: scripts/secret-scan-lint.sh --file .secretscanignore
# Strict scan: scripts/secret-scan.sh --diff origin/main --strict
# allow: gsd-core/workflows/plan-phase.md reason="contains illustrative DATABASE_URL/REDIS_URL example strings used as documentation placeholders — not real credentials" owner="@open-gsd/maintainers" expires="2027-06-30"
gsd-core/workflows/plan-phase.md
# allow: gsd-core/references/verification-patterns.md reason="documents stub/placeholder RED-FLAG examples for env vars (illustrative Stripe test-key, database-URL and API-key placeholders shown as what NOT to ship) — not real credentials" owner="@open-gsd/maintainers" expires="2027-06-30"
gsd-core/references/verification-patterns.md
# allow: docs/zh-CN/references/verification-patterns.md reason="translated copy of the English verification-patterns.md — carries the same illustrative placeholder examples (Stripe test-key, database-URL, API-key) as what NOT to ship" owner="@open-gsd/maintainers" expires="2027-06-30"
docs/zh-CN/references/verification-patterns.md