# Docs: https://docs.github.com/en/authentication
# Format: ghr_ prefix followed by 36 alphanumeric characters
# Prefix: ghr_
[detector]
id = "github-refresh-token"
name = "GitHub Refresh Token"
service = "github"
severity = "critical"
ml = { match_mode = "lift", entropy_mode = "disabled", weight = 1.0, context_radius_lines = 5 }
match_confidence = { literal_prefix_weight = 0.35, context_anchor_weight = 0.20, entropy_weight = 0.20, high_entropy_partial_weight = 0.12, moderate_entropy_threshold = 3.0, moderate_entropy_weight = 0.05, low_entropy_penalty_floor = 2.0, low_entropy_min_match_length = 10, low_entropy_penalty_multiplier = 0.60, keyword_nearby_weight = 0.10, sensitive_file_weight = 0.10, companion_weight = 0.05, very_high_entropy_margin = 1.2999999999999998, named_anchor_floor = 0.55, assignment_context_multiplier = 1.0, string_literal_context_multiplier = 0.9, unknown_context_multiplier = 0.8, documentation_context_multiplier = 0.3, comment_context_multiplier = 0.4, test_context_multiplier = 0.3, encrypted_context_multiplier = 0.05, soft_context_suppression_threshold = 0.5, encrypted_context_suppression_threshold = 0.8, post_match = { placeholder_multiplier = 0.05, minimum_byte_diversity = 0.1, low_diversity_multiplier = 0.1, maximum_repeat_ratio = 0.8, degenerate_run_min_length = 10, degenerate_repeat_multiplier = 0.1, fixture_path_multiplier = 0.5, ml_context_reapply_below = 0.95 } }
decode_transforms = { reverse_prefixes = ["ghr_"], caesar_prefixes = ["ghr_"] }
validators = [{ type = "crc32-base62", prefixes = ["ghr_"], entropy_len = 30, checksum_len = 6, reject_overlong = true, confidence_floor = 0.9 }]
keywords = ["ghr_"]
[[detector.patterns]]
regex = 'ghr_[A-Za-z0-9]{36}'
description = "GitHub Refresh Token (ghr_ prefix)"
[detector.verify]
method = "GET"
url = "https://api.github.com/user"
allowed_domains = ["api.github.com"]
[detector.verify.auth]
type = "bearer"
field = "match"
[[detector.verify.headers]]
name = "User-Agent"
value = "keyhog-secret-scanner/{{version}}"
[detector.verify.success]
status = 200
policy = "status_with_error_backstop"
[[detector.tests]]
test_positive = "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"
test_negative = "YOUR_API_KEY_HERE_PLACEHOLDER_VALUE"