chore(security): scrub dead admin token from doc + add gitleaks db-URL rule #161
No reviewers
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
gmackie/ForgeGraph!161
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "chore/security-scrub-token-gitleaks"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Final hygiene from the leaked-credential incident (both items are cleanup — no live exposure; the credentials involved are already dead).
1. Scrub the dead admin token from a committed doc
docs/plans/2026-05-06-forgejo-sync.mdembedded a Forgejo admin token in a setup example. Verified dead (HTTP 401 against the Forgejo API), so no server-side revocation is needed — replaced the literal token with$FORGEJO_ADMIN_TOKEN. (The other leaked token, from the old.git/configremote URL, is also dead and already removed from the URL.)2. Add a gitleaks rule for DB connection strings
gitleaks's default rules do not match URL-form DB credentials (
postgres://user:PASSWORD@host) — that gap is exactly how the owner password sat in two committedwrangler.tomlfiles undetected. New.gitleaks.toml:[extend] useDefault = true+ adb-connection-string-inline-passwordrule (postgres/mysql/redis/mongodb).<password>,password,${VAR},$VAR) so examples don't false-positive.color.ui = alwaysgotcha that silently makes gitleaks scan zero commits.Verified: real leaked strings FLAGGED, placeholder/env-var forms allowlisted; TOML parses.
🤖 Generated with Claude Code