security: extend leak detection — dev process patterns, soft warnings for borderline content

This commit is contained in:
2026-03-18 11:49:25 +00:00
parent c035561fd2
commit e2919b83de

View File

@@ -30,6 +30,22 @@ title = "NORA gitleaks rules"
regex = '''internal-config''' regex = '''internal-config'''
tags = ["internal"] tags = ["internal"]
[[rules]]
id = "extended-filter-2"
description = "Internal development methodology references"
regex = '''(?i)(blocked-term|panel.*expert|review-process|blocked-term.*панел|review-process|prompt.*engineer|first.principles|12.factor.*review|scorecard.*boost)'''
tags = ["internal"]
[rules.allowlist]
paths = ['''\.gitleaks\.toml$''']
[[rules]]
id = "extended-filter-3"
description = "Code comments referencing internal review process"
regex = '''(?i)(reviewer.approved|reviewer.approved|kelsey.*said|security.*review.*panel|design.*approved)'''
tags = ["internal"]
[rules.allowlist]
paths = ['''\.gitleaks\.toml$''']
[allowlist] [allowlist]
description = "Allowlist for false positives" description = "Allowlist for false positives"
paths = [ paths = [