diff --git a/.gitleaksignore b/.gitleaksignore new file mode 100644 index 00000000..b9684a1e --- /dev/null +++ b/.gitleaksignore @@ -0,0 +1,6 @@ +# gitleaks false-positive allowlist (fingerprints). +# Format: one fingerprint per line. `gitleaks detect --report-format json` outputs them. + +# Nuclei docs `-u http://...` — nuclei's -u flag is "target URL", not curl basic-auth. +# Rule `curl-auth-user` matches the pattern but it's not authentication. +f696ca50266eb1c2974b5fc89f6fa585edaf4b6b:docs/security/nuclei-setup.md:curl-auth-user:27