* Sanitize test fixtures, add developer .env guidance, and add gitleaks workflow
- Replace realistic-looking AWS keys and PEM fixtures in unit tests with synthetic placeholders to avoid false positives from secret scanners.
- Add docs/DEVELOPER-ENVIRONMENT.md describing postinstall .env behavior and remediation guidance.
- Add .github/workflows/gitleaks.yml to run gitleaks on pull requests.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add gitleaks baseline and CI baseline support; update ignore and PR body\n\n- Copy gitleaks-local.json -> gitleaks-baseline.json\n- Add --baseline-path to workflow\n- Allowlist baseline in .gitleaks.toml\n- Ignore gitleaks-local.json\n- Add PR_BODY.md with scan summary\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* chore(security): fix gitleaks config, drop redundant baseline/CI, clean doc artifacts
- Fix the malformed .gitleaks.toml [[rules]] block: an inline [rules.allowlist]
with only paths (no regex/path at rule level) made gitleaks refuse to load the
config (`FTL Failed to load config ... both |regex| and |path| are empty`),
turning the project's blocking check-secrets ratchet into a hard failure.
Verified: check-secrets config now loads and exits 0.
- Reconcile with the existing gitleaks gate: remove the redundant
.github/workflows/gitleaks.yml and root gitleaks-baseline.json (a second,
differently-scoped scanning mechanism + an unreviewed 430-finding blanket
baseline) — the project already runs scripts/check/check-secrets.mjs as a
blocking ratchet in ci.yml/quality.yml and its .gitleaks.toml policy is to fix
real findings, not blanket-allowlist them.
- Remove the stray PR_BODY.md automation artifact from the repo root.
- Fix the duplicated <div align="center"> tag in README.md.
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
---------
Co-authored-by: OmniRoute Bot <noreply@omniroute.local>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: blarovse <312250233+blarovse@users.noreply.github.com>
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>