gitleaks:掃 Working Tree、Git History 與 CI Diff 的 Secret Detection
gitleaks 用 rules、regex、entropy 與 allowlists 掃檔案或 Git patches;找到 secret 後第一步是 revoke/rotate,而不是只刪檔或改寫 history。
gitleaks 用 rules、regex、entropy 與 allowlists 掃檔案或 Git patches;找到 secret 後第一步是 revoke/rotate,而不是只刪檔或改寫 history。
SecretRef 讓憑證不必以明文躺在設定檔裡,模型呼叫鏈上看到的是 process-local 的哨兵值。但官方講得很白:這不是程序隔離——真正的值仍在同一個程序的記憶體裡,而且 agent 讀得到的任何明文檔案都繞過了這層保護。