Security: scrub host/server/org identifiers + token from files and history; add scan allowlists for the project's own public names and test corpus

This commit is contained in:
renefichtmueller 2026-06-23 22:47:52 -01:00
parent 266d45733d
commit cbde0363a6
2 changed files with 15 additions and 0 deletions

5
.gitleaks.toml Normal file
View File

@ -0,0 +1,5 @@
title="ShieldX"
[extend]
useDefault=true
[allowlist]
paths=['''.*\.test\.(ts|js)$''','''tests/.*''']

10
.security-scan-allowlist Normal file
View File

@ -0,0 +1,10 @@
[Ss]hield[Xx]
/opt/
[Pp]eer[Cc]ortex
eo-global-pulse
\bn8n\b
@gmail\.com
s3cr3t
prod-db
connectionString
admin:s3cr3t