v3.2.0
Named deny groups for leaks
The leaks config could classify exceptions by directory but never by term
class, so the only cheap way to quiet a private repo saturated with your own
footprint vocabulary was ignore = ["**"] — which also blinded the scan to terms
that must not appear in any repo.
[[group]]blocks are named deny lists (name+terms+regex).
Top-levelterms/regexare the implicit, reserveddefaultgroup.[[dir]].ignore_groupsdecides which groups anignoreglob silences. It
replaces the default list rather than extending it; absent, it means
["default"], so every existing config behaves exactly as before.defaultis
itself a legal entry — naming it alongside another group restores whole-file
skipping.allow/allow_regexare unchanged and are not group-scoped: naming a string
still suppresses it whatever group it is in.docgraph leaks-rulesexports every group's vocabulary, so a history scrub
covers grouped terms too.
regex = ['(?-i)AKIA[0-9A-Z]{16}'] # default group: secret shapes
[[group]]
name = "footprint"
terms = ["acme-host", "/Users/you"]
[[dir]]
path = "/abs/path/to/private-repo"
ignore = ["**"]
ignore_groups = ["footprint"] # footprint is fine here; secrets stay liveUnknown keys in leaks.toml are now fatal
This can block a push on an existing config, so it is the change to read.
leaks.toml previously decoded unknown keys silently. That was tolerable when a
typo merely killed a rule; with ignore_groups it inverts which class is
silenced — ignore_group (singular) decodes clean, leaves the field empty, and
the ["default"] default then suppresses your secret shapes while leaving the
group you meant to silence live. A one-character typo, no warning.
Unknown keys now exit 2 with the offending keys named
(unknown key(s): dir.ignore_group), consistent with the existing
malformed-config-is-fatal contract. An absent config is still non-fatal, so
CI and fresh clones are unaffected.
If your leaks.toml carries a stray or legacy key, the first push after
upgrading will fail with that message — remove the key. A [log] table belongs
in config.toml, not leaks.toml, and is the most likely offender.
Also fatal
A [[group]] with no usable terms or regex. It would otherwise register as a
defined group, so an ignore_groups naming it would filter nothing and leave the
blanket ignore it was written for completely inert.
Upgrading
Nothing to do beyond the unknown-key check above. Grouping is opt-in; a config
with no [[group]] blocks behaves identically to 3.1.1.