1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
| {
"$comment": "GateTest scanner config for Gluecron.com. Sibling to the protected .gatetest.json marker file — do not merge them. Scanner reads both.",
"project": {
"name": "gluecron",
"root": "."
},
"triggers": {
"pullRequest": {
"enabled": true,
"branchPatterns": [
"main",
"master",
"claude/*",
"claude/**",
"gatetest/*",
"gatetest/**"
],
"reason": "Every PR opened from agent branch prefixes (claude/*, gatetest/*) must be auto-scanned. Targets the lowercase main on Gluecron."
},
"push": {
"enabled": true,
"branchPatterns": ["main", "master"]
},
"schedule": [
{
"name": "empire-smoke",
"cron": "*/5 * * * *",
"command": "bun run integrations/smoke/empire-smoke.ts",
"reason": "Runs the cross-repo smoke harness every 5 minutes. Surfaces cert / DNS / response-code regressions before a human notices. Owned by agent 6 — ensure integrations/smoke/empire-smoke.ts exists before flipping schedule to required.",
"severity": "error",
"timeoutSeconds": 180,
"allowMissing": true
}
]
},
"rules": {
"schemaRegressionGate": {
"enabled": true,
"severity": "error",
"when": {
"pathsChanged": [
"src/**/*.ts",
"src/**/*.tsx",
"**/schema.ts",
"**/schema.prisma",
"**/*.types.ts",
"**/types/**/*.ts"
]
},
"command": "npm run typecheck --if-present",
"scope": "dependents",
"reason": "When exported types or DB schemas move, re-typecheck every dependent module so the ripple doesn't land silently."
},
"secretLeak": {
"enabled": true,
"severity": "error",
"scanEveryPR": true,
"patterns": [
"\\.env(\\..+)?$",
"\\.env\\.local$",
"\\.env\\.production$",
".*\\.pem$",
".*\\.key$",
"(^|/)id_rsa$",
"(^|/)id_ed25519$",
"(^|/)\\.pgpass$",
"(^|/)credentials\\.json$",
"(^|/)service-account.*\\.json$"
],
"contentPatterns": [
"AKIA[0-9A-Z]{16}",
"ghp_[A-Za-z0-9]{36,}",
"gho_[A-Za-z0-9]{36,}",
"github_pat_[A-Za-z0-9_]{80,}",
"sk-ant-[A-Za-z0-9_-]{40,}",
"sk-[A-Za-z0-9]{40,}",
"xox[baprs]-[A-Za-z0-9-]{10,}",
"-----BEGIN (RSA |OPENSSH |EC |DSA |PGP )?PRIVATE KEY-----"
],
"reason": "Verify .env / *.pem / id_rsa / hardcoded tokens don't slip through."
}
},
"ignore": {
"paths": [
"**/node_modules/**",
"**/.turbo/**",
"**/.vercel/**",
"**/.output/**",
"**/dist/**",
"**/build/**",
"**/*.min.js",
"**/*.min.css",
"**/*.map",
"coverage/**",
"src/__tests__/**",
"scripts/**",
"cli/**",
"vscode-extension/**"
]
}
}
|