Skip to content

Commit 1248df5

Browse files
Merge pull request #82 from NHSDigital/mesh-2025-add-check-secret-patterns
mesh-2025: added additional secret patterns
2 parents 162ac13 + e9f967f commit 1248df5

File tree

2 files changed

+6
-2
lines changed

2 files changed

+6
-2
lines changed

.gitallowed

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,3 +2,6 @@
22
token: \$\{\{ secrets.GITHUB_TOKEN \}\}
33
"token": response.get\("SessionToken"\)
44
token=credentials\["token"\]
5+
6+
.*(GITHUB|SONAR)_TOKEN: \$\{\{ secrets.(GITHUB|SONAR)_TOKEN \}\}
7+
.*asttokens = ">=2.1.0"

.gitdisallowed

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,8 @@ AIza[0-9A-Za-z\\-_]{35}
1515
-----BEGIN[[:blank:]]CERTIFICATE-----
1616
[0-9a-fA-F]{1,4}:[0-9a-fA-F]{1,4}:[0-9a-fA-F]{1,4}:[0-9a-fA-F]{1,4}:[0-9a-fA-F]{1,4}:[0-9a-fA-F]{1,4}:[0-9a-fA-F]{1,4}:[0-9a-fA-F]{1,4}
1717
(CLIENT|client|Client)(_|\s)(SECRET|secret|Secret)\s*(:|=>|=)\s*("|')?(\{)?[0-9a-fA-F]{8}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{12}(\})?("|')?
18-
("|'?)[Pp][Aa][Ss][Ss][Ww][Oo][Rr][Dd]("|'?)\s*(=|:)\s*.+
19-
("|'?)[Tt][Oo][Kk][Ee][Nn]("|'?)\s*(=|:)\s*.+
18+
.*("|'?)[Pp][Aa][Ss][Ss][Ww][Oo][Rr][Dd](S|s?)("|'?)\s*(=|:)\s*.+
19+
.*("|'?)[Tt][Oo][Kk][Ee][Nn]("|'?)(S|s?)\s*(=|:)\s*.+
20+
.*("|'?)[Ss][Ee][Cc][Rr][Ee][Tt](S|s?)("|'?)\s*(=|:)\s*.+
2021

2122
###_NOTE_REMOVED_PREVIOUS_IP_RULE_:[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}###

0 commit comments

Comments
 (0)