Conversation
Three layers keep credentials out of the repository: - lefthook pre-commit scans staged changes with gitleaks - lefthook pre-push scans commits not yet on any remote - CI secret-scan scans the PR range, so --no-verify cannot skip it .gitleaks.toml extends the default rules with hardcoded-password-literal, which catches Wi-Fi passphrases the defaults miss. It is the canonical copy for the other gHashTag repos. The OSF OAuth token is removed from the research summary; it stays in history and is being revoked at osf.io. Closes #6432 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
This was referenced Oct 5, 2026
This was referenced Oct 5, 2026
gHashTag
added a commit
that referenced
this pull request
Oct 5, 2026
Refs #6510 Added through the contents API, not a local commit: once this file exists in a worktree, the gate it installs rejects every commit that adds a protected gate file, including this one. --no-verify was not used. Union-compatible with #6433 (secret-gate): merging is a union of commands. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Owner
Author
|
Coordination note: #6511 (Only t27 gate) also adds lefthook.yml, with an |
This was referenced Oct 5, 2026
Merged
Closed
This was referenced Oct 6, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #6432
What changed
lefthook.yml: pre-commit runs gitleaks on staged changes; pre-push runs it on every commit not yet on a remote. A missing gitleaks fails the hook rather than skipping it..gitleaks.toml: the default gitleaks rules plushardcoded-password-literal, which catches the Wi-Fi passphrases the defaults miss (the trinity-fpga leak, Host health monitor (R-HS-41) #899 there). This is the canonical copy for the other gHashTag repos. The allowlists cover only verified non-secrets: the generated symbol inventory, a GF16 hex constant, one prose NOTE, and compiler flags.secret-scan.yml: the existing job (Solana keys, test-ledger, home paths) is unchanged. A newgitleaksjob scans the event's commit range, so--no-verifycannot land a credential.research/gamma-hypotheses/OSF-upload-summary.md.SECURITY.mddocuments the three layers and the one-time setup (brew install gitleaks lefthook && lefthook install).Verified
gitleaks dir . --config .gitleaks.tomlreports 0 findings on this tree.wifi_password = "..."is blocked (exit 1); a clean index passes.Not done here
The OSF token remains in history and has to be revoked at osf.io.
🤖 Generated with Claude Code