| 482 | // Messages name the file and the pattern class but NEVER echo the matched |
| 483 | // value, since leaking a real secret back into the context window would |
| 484 | // defeat the purpose of the sweep. |
| 485 | |
| 486 | // Named credential shapes. Anchored prefixes with real length requirements |
| 487 | // so substrings inside ordinary identifiers (the sk- trap: "task_created") |
| 488 | // can never match. |
| 489 | const SECRET_PATTERNS = [ |
| 490 | { |
| 491 | cls: 'aws-access-key-id', |
| 492 | regex: /\bAKIA[A-Z0-9]{16}\b/, |
| 493 | label: 'AWS access key ID', |
| 494 | }, |
| 495 | { |
| 496 | cls: 'github-token', |
| 497 | regex: /\bghp_[A-Za-z0-9]{36}\b/, |