Skip to content

security: lefthook + gitleaks secret gate (pre-commit, pre-push, CI); remove OSF token - #6433

Open
gHashTag wants to merge 1 commit into
masterfrom
security/secret-gate
Open

gHashTag wants to merge 1 commit into
masterfrom
security/secret-gate

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Closes #6432

What changed

  • lefthook.yml: pre-commit runs gitleaks on staged changes; pre-push runs it on every commit not yet on a remote. A missing gitleaks fails the hook rather than skipping it.
  • .gitleaks.toml: the default gitleaks rules plus hardcoded-password-literal, which catches the Wi-Fi passphrases the defaults miss (the trinity-fpga leak, Host health monitor (R-HS-41) #899 there). This is the canonical copy for the other gHashTag repos. The allowlists cover only verified non-secrets: the generated symbol inventory, a GF16 hex constant, one prose NOTE, and compiler flags.
  • secret-scan.yml: the existing job (Solana keys, test-ledger, home paths) is unchanged. A new gitleaks job scans the event's commit range, so --no-verify cannot land a credential.
  • OSF token removed from research/gamma-hypotheses/OSF-upload-summary.md.
  • SECURITY.md documents the three layers and the one-time setup (brew install gitleaks lefthook && lefthook install).

Verified

  • gitleaks dir . --config .gitleaks.toml reports 0 findings on this tree.
  • A staged fake wifi_password = "..." is blocked (exit 1); a clean index passes.
  • This commit went through the lefthook pre-commit hook, and the push went through pre-push (1 commit scanned, no leaks).

Not done here

The OSF token remains in history and has to be revoked at osf.io.

🤖 Generated with Claude Code

Three layers keep credentials out of the repository:
- lefthook pre-commit scans staged changes with gitleaks
- lefthook pre-push scans commits not yet on any remote
- CI secret-scan scans the PR range, so --no-verify cannot skip it

.gitleaks.toml extends the default rules with hardcoded-password-literal,
which catches Wi-Fi passphrases the defaults miss. It is the canonical
copy for the other gHashTag repos.

The OSF OAuth token is removed from the research summary; it stays in
history and is being revoked at osf.io.

Closes #6432

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-05 14:06:34 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 41
PRs with All Checks Green 9
READY 8
FAILING 41
PENDING 0
NO CHECKS YET 0

These columns do not partition: 8 + 41 + 0 + 0 = 49, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=8597b6ded596 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

gHashTag added a commit that referenced this pull request Oct 5, 2026
Refs #6510

Added through the contents API, not a local commit: once this file exists
in a worktree, the gate it installs rejects every commit that adds a
protected gate file, including this one. --no-verify was not used.
Union-compatible with #6433 (secret-gate): merging is a union of commands.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@gHashTag

gHashTag commented Oct 5, 2026

Copy link
Copy Markdown
Owner Author

Coordination note: #6511 (Only t27 gate) also adds lefthook.yml, with an own-language command on pre-commit and pre-push. The two files merge as a union of the commands: maps; neither PR touches the other's command. Whichever lands second should rebase and keep both secret-gate and own-language.

This was referenced Oct 6, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security: lefthook + gitleaks secret gate (pre-commit, pre-push, CI); remove OSF token

1 participant