Skip to content

Deny Read/Grep access to secret-shaped files - #5

Merged
lorenzoliuzzo merged 2 commits into
mainfrom
chore/claude-secret-deny-patterns
Jul 8, 2026
Merged

Deny Read/Grep access to secret-shaped files#5
lorenzoliuzzo merged 2 commits into
mainfrom
chore/claude-secret-deny-patterns

Conversation

@lorenzoliuzzo

Copy link
Copy Markdown
Contributor

Adds a .claude/settings.json with the same permissions.deny block used in the fleet-dispatch workspace root, so sessions opened directly in this repo (not just at the MyThingsLab workspace root) block Read/Grep on .env*, *.pem, *.key, *credentials*, *secret*, id_rsa, id_ed25519.

Part of a fleet-wide backfill closing a gap found while testing the deny patterns: repo-scoped Claude Code sessions didn't inherit the parent workspace's protection.

lorenzoliuzzo and others added 2 commits July 8, 2026 19:51
Adds the same permissions.deny block already in the fleet-dispatch
workspace root, so a session opened directly in this repo also blocks
Read/Grep on .env*, *.pem, *.key, *credentials*, *secret*, id_rsa,
id_ed25519 -- previously only sessions started at the MyThingsLab
workspace root inherited this protection.
@codecov

codecov Bot commented Jul 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@lorenzoliuzzo
lorenzoliuzzo merged commit f8ca00a into main Jul 8, 2026
2 checks passed
@lorenzoliuzzo
lorenzoliuzzo deleted the chore/claude-secret-deny-patterns branch July 12, 2026 12:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant