What to build
Add a scanner-level regex filter that detects common secret patterns (API keys, tokens, private keys) before indexing. Files containing matches are skipped with a warning log.
Decision: Deferred for later
- Approach: A (Scanner-level regex filter). Small set of well-known patterns catches 90% of cases with zero dependencies.
- Not now: Keep in mind for later implementation. Secrets should not be indexed.
Proposed patterns (for future implementation)
- AWS access keys (
AKIA[0-9A-Z]{16})
- GitHub tokens (
ghp_[a-zA-Z0-9]{36})
- Private key headers (
-----BEGIN (RSA )?PRIVATE KEY-----)
- Generic API key patterns (
api[_-]?key\s*[:=]\s*['"][a-zA-Z0-9]{20,}['"])
- Password assignments (
password\s*[:=]\s*['"][^'"]{8,}['"])
Acceptance criteria (for future implementation)
Blocked by
None - can start when prioritized
What to build
Add a scanner-level regex filter that detects common secret patterns (API keys, tokens, private keys) before indexing. Files containing matches are skipped with a warning log.
Decision: Deferred for later
Proposed patterns (for future implementation)
AKIA[0-9A-Z]{16})ghp_[a-zA-Z0-9]{36})-----BEGIN (RSA )?PRIVATE KEY-----)api[_-]?key\s*[:=]\s*['"][a-zA-Z0-9]{20,}['"])password\s*[:=]\s*['"][^'"]{8,}['"])Acceptance criteria (for future implementation)
--jsonoutput includes skipped secrets in resultconfig.secretPatternsBlocked by
None - can start when prioritized