mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-09-29 01:42:21 +00:00
OpenRouter API keys have the shape sk-or-v1-<64 hex>. The existing entropy-based redactor requires Shannon entropy above 4.5 bits/byte, but pure-hex strings max out at 4.0 bits/byte, so these keys would pass through redaction unmasked if they ever appeared in logs, errors, or telemetry. Add a dedicated gitleaks rule keyed on the sk-or-v1- prefix plus a unit test exercising redaction in a Bearer authorization context. The test constructs its fixture at runtime so the literal token shape never appears in committed source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| crates | ||
| packages/fabro-api-client | ||