litellm/.gitguardian.yaml
Alexsander Hamir 8b69d7ca48 Fix bad practice: replace real-looking API keys in cache_dashboard comments with example patterns
- Replace high-entropy mock API keys in comments with sk-example-... pattern
- Remove unnecessary gitguardian ignore entries for bad practices
2026-01-05 16:42:25 -08:00

112 lines
3.4 KiB
YAML

version: 2
secret:
ignored_paths:
- "**/*.whl"
- "**/*.pyc"
- "**/__pycache__/**"
- "**/node_modules/**"
- "**/dist/**"
- "**/build/**"
- "**/.git/**"
- "**/venv/**"
- "**/.venv/**"
# Large data/metadata files that don't need scanning
- "**/model_prices_and_context_window*.json"
- "**/*_metadata/*.txt"
- "**/tokenizers/*.json"
- "**/tokenizers/*"
- "miniconda.sh"
# Build outputs and static assets
- "litellm/proxy/_experimental/out/**"
- "ui/litellm-dashboard/public/**"
- "**/swagger/*.js"
- "**/*.woff"
- "**/*.woff2"
- "**/*.avif"
- "**/*.webp"
# Test files and fixtures
- "**/tests/**/*.py"
- "**/test_*.py"
- "**/*_test.py"
- "**/*.test.tsx"
- "**/*.test.ts"
- "**/*.spec.tsx"
- "**/*.spec.ts"
- "**/tests/**/data_map.txt"
- "tests/**/*.txt"
# Example and documentation files
- "cookbook/**/*.ipynb"
- "litellm/proxy/_super_secret_config.yaml"
- "docs/**"
- "**/*.md"
- "**/*.lock"
- "poetry.lock"
- "package-lock.json"
# Ignore false positives by SHA256 hash or pattern
ignored_matches:
# Specific false positives (SHA256-based)
- name: GCS pub/sub test folder name
match: 75f377c456eede69e5f6e47399ccee6016a2a93cc5dd11db09cc5b1359ae569a
- name: Environment variable reference APORIA_API_KEY_1
match: e2ddeb8b88eca97a402559a2be2117764e11c074d86159ef9ad2375dea188094
- name: Environment variable reference APORIA_API_KEY_2
match: 09aa39a29e050b86603aa55138af1ff08fb86a4582aa965c1bd0672e1575e052
- name: OIDC CircleCI test path
match: feb3475e1f89a65b7b7815ac4ec597e18a9ec1847742ad445c36ca617b536e15
- name: OpenAI model identifier
match: c489000cf6c7600cee0eefb80ad0965f82921cfb47ece880930eb7e7635cf1f1
- name: Test Base64 Basic Auth header
match: 61bac0491f395040617df7ef6d06029eac4d92a4457ac784978db80d97be1ae0
- name: Test PostgreSQL password
match: 6e0d657eb1f0fbc40cf0b8f3c3873ef627cc9cb7c4108d1c07d979c04bc8a4bb
- name: Test Bearer token in load test
match: 2a0abc2b0c3c1760a51ffcdf8d6b1d384cef69af740504b1cfa82dd70cdc7ff9
- name: Inkeep API key in documentation
match: c366657791bfb5fc69045ec11d49452f09a0aebbc8648f94e2469b4025e29a75
- name: Langfuse test credentials
match: c39310f68cc3d3e22f7b298bb6353c4f45759adcc37080d8b7f4e535d3cfd7f4
- name: Test password in e2e fixtures
match: ce32b547202e209ec1dd50107b64be4cfcf2eb15c3b4f8e9dc611ef747af634f
# Test API key patterns
- name: Test API keys with sk-test prefix
match: sk-test-
- name: Mock API keys with sk-mock prefix
match: sk-mock-
- name: Fake API keys with sk-fake prefix
match: sk-fake-
- name: Generic test API key pattern
match: test-api-key
# Common test fixtures
- name: Test API key fixture 88dc28d0f03
match: 88dc28d0f030c55ed4ab77ed8faf098196cb1c05df778539800c9f1243fe6b4b
- name: Test API key fixture 40b7608ea43
match: 40b7608ea43423400d5b82bb5ee11042bfb2ed4655f05b5992b5abbc2f294931
- name: SHA256 empty string (test fixture)
match: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
- name: Test JWT token pattern
match: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9