# secret-patterns.tsv — checked-in pattern list for scripts/secret-scan.sh # # Format: # Blank lines and lines whose first field starts with '#' are ignored. # is optional; the only value today is "value", which tells the scanner # to run the matched value through its inert-value classifier (see # value_is_inert in secret-scan.sh) so bare identifiers, env refs and dotted # code access are not reported as credentials. Omit the column to report every # regex hit. # Matching is case-insensitive, so `API_KEY` and `api_key` both count. # # Add a rule here, never inline in secret-scan.sh: this file is the single # auditable list of what the guard considers credential-shaped. openai-key \bsk-[A-Za-z0-9_-]{16,} OpenAI/LiteLLM-style "sk-" secret key (also hyphenated sk-proj- keys) openrouter-key \bsk-or-v1-[A-Za-z0-9_-]{8,} OpenRouter API key stripe-live-key \bsk_live_[A-Za-z0-9]{8,} Stripe live secret key proxmox-token PVEAPIToken=[^[:space:]"']+ Proxmox API token literal bearer-token bearer[[:space:]]+["']?(«.{3,}»|[A-Za-z0-9_./+=-]{20,}) literal Bearer token (http header or prose) auth-header authorization:[[:space:]]+["']?(«.{3,}»|[A-Za-z0-9_./+=-]{20,}) Authorization header carrying a raw literal value private-key -----BEGIN [A-Z ]*PRIVATE KEY----- PEM private key block cred-prose credentials?[[:space:]]*[:=][[:space:]]*[^[:space:]] prose credential line carrying a value secret-assign (api[_-]?key|apikey|passwd|password|secret|token)s?["']?[[:space:]]*[:=][[:space:]]*["']?(«.{3,}»|[A-Za-z0-9_./+=-]{8,}) credential assignment carrying a literal value value