# Docs: https://docs.github.com/en/webhooks/using-webhooks/validating-webhook-deliveries
# Format: User-defined string (typically 20-100 characters) used for HMAC-SHA256 signature verification
# Verify: no public verification endpoint (local signature verification using X-Hub-Signature-256 header)
# Prefix: none (requires context anchoring)
[detector]
id = "github-webhook-secret"
name = "GitHub Webhook Secret"
service = "github"
severity = "high"
ml = { match_mode = "lift", entropy_mode = "disabled", weight = 1.0, context_radius_lines = 5 }
match_confidence = { literal_prefix_weight = 0.35, context_anchor_weight = 0.20, entropy_weight = 0.20, high_entropy_partial_weight = 0.12, moderate_entropy_threshold = 3.0, moderate_entropy_weight = 0.05, low_entropy_penalty_floor = 2.0, low_entropy_min_match_length = 10, low_entropy_penalty_multiplier = 0.60, keyword_nearby_weight = 0.10, sensitive_file_weight = 0.10, companion_weight = 0.05, very_high_entropy_margin = 1.2999999999999998, named_anchor_floor = 0.55, assignment_context_multiplier = 1.0, string_literal_context_multiplier = 0.9, unknown_context_multiplier = 0.8, documentation_context_multiplier = 0.3, comment_context_multiplier = 0.4, test_context_multiplier = 0.3, encrypted_context_multiplier = 0.05, soft_context_suppression_threshold = 0.5, encrypted_context_suppression_threshold = 0.8, post_match = { placeholder_multiplier = 0.05, minimum_byte_diversity = 0.1, low_diversity_multiplier = 0.1, maximum_repeat_ratio = 0.8, degenerate_run_min_length = 10, degenerate_repeat_multiplier = 0.1, fixture_path_multiplier = 0.5, ml_context_reapply_below = 0.95 } }
keywords = ["GITHUB_WEBHOOK_SECRET", "github_webhook_secret", "webhook_secret", "X-Hub-Signature-256"]
[[detector.patterns]]
regex = "(?:GITHUB|github)[._-]?(?:WEBHOOK|webhook|HOOK|hook)[._-]?(?:SECRET|secret|TOKEN|token)[=:\\s\"'']+([a-zA-Z0-9_-]{20,100})"
description = "GitHub webhook secret with context anchor"
group = 1
[[detector.patterns]]
# `\b` is load-bearing: a bare `gh` matches at the tail of an identifier, so
# `LEIGH_WEBHOOK_SECRET=` was reported as a GitHub webhook secret.
regex = '''(?:(?:^|[^A-Za-z])gh|github)[._-]?webhook[_\-\s]*secret[=:\s"'']+([a-zA-Z0-9_-]{20,100})'''
required_literals = ["webhook"]
description = "GitHub webhook secret with abbreviated context"
group = 1
[[detector.tests]]
test_positive = "GITHUB_WEBHOOK_SECRET=N-hyshMKLyl_Pj_laamriw0VaNok"
test_negative = "GITHUB_WEBHOOK_SECRET=YOUR_API_KEY_HERE_PLACEHOLDER_VALUE"