fabro/lib
Scott Werner 674fc5871a feat(redact): add gitleaks rule for OpenRouter API keys
OpenRouter API keys have the shape sk-or-v1-<64 hex>. The existing
entropy-based redactor requires Shannon entropy above 4.5 bits/byte,
but pure-hex strings max out at 4.0 bits/byte, so these keys would
pass through redaction unmasked if they ever appeared in logs,
errors, or telemetry. Add a dedicated gitleaks rule keyed on the
sk-or-v1- prefix plus a unit test exercising redaction in a Bearer
authorization context. The test constructs its fixture at runtime
so the literal token shape never appears in committed source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-28 16:53:34 -04:00
..
crates feat(redact): add gitleaks rule for OpenRouter API keys 2026-05-28 16:53:34 -04:00
packages/fabro-api-client refactor: Remove inbound IP allowlisting (#443) 2026-05-27 22:29:08 -04:00