Skip to content

v3.2.0

Choose a tag to compare

@Lockyc Lockyc released this 12 Aug 02:32
· 14 commits to main since this release

Named deny groups for leaks

The leaks config could classify exceptions by directory but never by term
class
, so the only cheap way to quiet a private repo saturated with your own
footprint vocabulary was ignore = ["**"] — which also blinded the scan to terms
that must not appear in any repo.

  • [[group]] blocks are named deny lists (name + terms + regex).
    Top-level terms/regex are the implicit, reserved default group.
  • [[dir]].ignore_groups decides which groups an ignore glob silences. It
    replaces the default list rather than extending it; absent, it means
    ["default"], so every existing config behaves exactly as before. default is
    itself a legal entry — naming it alongside another group restores whole-file
    skipping.
  • allow / allow_regex are unchanged and are not group-scoped: naming a string
    still suppresses it whatever group it is in.
  • docgraph leaks-rules exports every group's vocabulary, so a history scrub
    covers grouped terms too.
regex = ['(?-i)AKIA[0-9A-Z]{16}']   # default group: secret shapes

[[group]]
name  = "footprint"
terms = ["acme-host", "/Users/you"]

[[dir]]
path          = "/abs/path/to/private-repo"
ignore        = ["**"]
ignore_groups = ["footprint"]     # footprint is fine here; secrets stay live

Unknown keys in leaks.toml are now fatal

This can block a push on an existing config, so it is the change to read.
leaks.toml previously decoded unknown keys silently. That was tolerable when a
typo merely killed a rule; with ignore_groups it inverts which class is
silenced — ignore_group (singular) decodes clean, leaves the field empty, and
the ["default"] default then suppresses your secret shapes while leaving the
group you meant to silence live. A one-character typo, no warning.

Unknown keys now exit 2 with the offending keys named
(unknown key(s): dir.ignore_group), consistent with the existing
malformed-config-is-fatal contract. An absent config is still non-fatal, so
CI and fresh clones are unaffected.

If your leaks.toml carries a stray or legacy key, the first push after
upgrading will fail with that message — remove the key. A [log] table belongs
in config.toml, not leaks.toml, and is the most likely offender.

Also fatal

A [[group]] with no usable terms or regex. It would otherwise register as a
defined group, so an ignore_groups naming it would filter nothing and leave the
blanket ignore it was written for completely inert.

Upgrading

Nothing to do beyond the unknown-key check above. Grouping is opt-in; a config
with no [[group]] blocks behaves identically to 3.1.1.