keyhog-core 0.5.73

keyhog-core: shared data model and detector specifications for the KeyHog secret scanner
Documentation
# Docs: https://docs.gitlab.com/security/tokens/ (runner authentication token)
# Format: glrt- prefix + 20 base64url-safe chars (GitLab 16.0+ replaced the
#         old registration token). Routable variant: glrt-t<digit>_<body>.<suffix>.
# Verify: POST https://gitlab.com/api/v4/runners/verify with `token` form field.
# Prefix: glrt-

[detector]
id = "gitlab-runner-authentication-token"
name = "GitLab Runner Authentication Token"
service = "gitlab"
severity = "high"
ml = { match_mode = "lift", entropy_mode = "disabled", weight = 1.0, context_radius_lines = 5 }
match_confidence = { literal_prefix_weight = 0.35, context_anchor_weight = 0.20, entropy_weight = 0.20, high_entropy_partial_weight = 0.12, moderate_entropy_threshold = 3.0, moderate_entropy_weight = 0.05, low_entropy_penalty_floor = 2.0, low_entropy_min_match_length = 10, low_entropy_penalty_multiplier = 0.60, keyword_nearby_weight = 0.10, sensitive_file_weight = 0.10, companion_weight = 0.05, very_high_entropy_margin = 1.2999999999999998, named_anchor_floor = 0.55, assignment_context_multiplier = 1.0, string_literal_context_multiplier = 0.9, unknown_context_multiplier = 0.8, documentation_context_multiplier = 0.3, comment_context_multiplier = 0.4, test_context_multiplier = 0.3, encrypted_context_multiplier = 0.05, soft_context_suppression_threshold = 0.5, encrypted_context_suppression_threshold = 0.8, post_match = { placeholder_multiplier = 0.05, minimum_byte_diversity = 0.1, low_diversity_multiplier = 0.1, maximum_repeat_ratio = 0.8, degenerate_run_min_length = 10, degenerate_repeat_multiplier = 0.1, fixture_path_multiplier = 0.5, ml_context_reapply_below = 0.95 } }
decode_transforms = { reverse_prefixes = ["glrt-"], caesar_prefixes = ["glrt-"] }
validators = [{ type = "pattern-shape", prefixes = ["glrt-"], allow_overlong = true }]
keywords = ["glrt-", "gitlab", "CI_SERVER_URL", "runner"]

[[detector.patterns]]
# Standard and versioned runner auth tokens use the same base64url family.
# Keep the supported 20-64-byte band beside its structural validator.
regex = 'glrt-[0-9a-zA-Z_.\-]{20,64}'
description = "GitLab runner authentication token (glrt- prefix, 20-64 chars)"

[[detector.patterns]]
# Routable runner auth token: glrt-t<digit>_<27-300 chars>.<9 lower-hex/alnum>
# (gitleaks `gitlab-runner-authentication-token-routable`).
regex = 'glrt-t[0-9]_[0-9a-zA-Z_\-]{27,300}\.[0-9a-z]{9}'
description = "GitLab routable runner authentication token (glrt-t<n>_ prefix)"

[detector.verify]
method = "POST"
url = "https://gitlab.com/api/v4/runners/verify"
allowed_domains = ["gitlab.com"]

[detector.verify.auth]
type = "query"
param = "token"
field = "match"

[detector.verify.success]
status = 200
policy = "status_with_error_backstop"

[[detector.tests]]
test_positive = "glrt-2CR8_eVxiioB1QmzPZwa"
test_negative = "NOT_A_SECRET=totally_benign_example_value_123456"