mirror of
https://github.com/Jeuners/ECC.git
synced 2026-09-09 15:02:30 +02:00
fix: detect Anthropic API keys (sk-ant-...) in pre-commit secret scan (#2529)
The existing OpenAI pattern sk-[a-zA-Z0-9]{20,} never matches real
Anthropic keys: their sk-ant-api03-... format contains hyphens, which
break the character class before reaching the 20-char threshold. Keys
from the fastest-growing Claude Code user base slipped through the scan.
Adds a dedicated sk-ant-[a-zA-Z0-9_-]{20,} pattern (checked before the
OpenAI one) and extends the staged-secrets test with a realistic
Anthropic key fixture.
This commit is contained in:
parent
a1bf029cbf
commit
8348fb5387
2 changed files with 3 additions and 0 deletions
|
|
@ -212,6 +212,7 @@ if (test('blocks commits with staged secret patterns across checkable files', ()
|
|||
inTempRepo(repoDir => {
|
||||
writeAndStage(repoDir, 'index.js', [
|
||||
"const openai = 'sk-abcdefghijklmnopqrstuvwxyz';",
|
||||
"const anthropic = 'sk-ant-api03-AbCdEf-GhIjKlMnOpQrStUvWx_Yz012345';",
|
||||
"const token = 'ghp_abcdefghijklmnopqrstuvwxyzABCDEFGHIJ';",
|
||||
''
|
||||
].join('\n'));
|
||||
|
|
@ -227,6 +228,7 @@ if (test('blocks commits with staged secret patterns across checkable files', ()
|
|||
assert.strictEqual(result.output, input);
|
||||
assert.strictEqual(result.exitCode, 2);
|
||||
assert.ok(stderr.includes('Potential OpenAI API key'), `expected OpenAI secret warning, got: ${stderr}`);
|
||||
assert.ok(stderr.includes('Potential Anthropic API key'), `expected Anthropic key warning, got: ${stderr}`);
|
||||
assert.ok(stderr.includes('Potential GitHub PAT'), `expected GitHub PAT warning, got: ${stderr}`);
|
||||
assert.ok(stderr.includes('Potential AWS Access Key'), `expected AWS key warning, got: ${stderr}`);
|
||||
assert.ok(stderr.includes('Potential API key'), `expected generic API key warning, got: ${stderr}`);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue