- kind: regex
pattern: '\b(glpat-[a-zA-Z0-9\-=_]{20,22})\b'
category: auth_token
label: gitlab_personal_token_v2
- kind: regex
pattern: '\b(glpat-[a-zA-Z0-9\-=_]{27,300}\.[0-9a-z]{2}\.[a-z0-9]{9})\b'
category: auth_token
label: gitlab_personal_token_v3
- kind: regex
pattern: '\bglcbt-\d{2}-[A-Za-z0-9_-]{20}\b'
category: auth_token
label: gitlab_ci_job_token
- kind: regex
pattern: '\bgldt-[A-Za-z0-9_-]{20}\b'
category: auth_token
label: gitlab_deploy_token
- kind: regex
pattern: '\bglft-[A-Za-z0-9_-]{20}\b'
category: auth_token
label: gitlab_feed_token
- kind: regex
pattern: '\bglrt-[A-Za-z0-9_-]{20}\b'
category: auth_token
label: gitlab_runner_token
- kind: regex
pattern: '\bglsoat-[A-Za-z0-9_-]{20}\b'
category: auth_token
label: gitlab_scim_token
- kind: regex
pattern: '\bglagent-[A-Za-z0-9_-]{50,}\b'
category: auth_token
label: gitlab_agent_token
- kind: regex
pattern: '(?i)(?:gitlab[_-]?(?:secret|token|key|api|pat)|gl_token)[\s:="'']+([a-zA-Z0-9][a-zA-Z0-9\-=_]{19,21})\b'
category: auth_token
label: gitlab_context_token
- kind: regex
pattern: '(?i)(?:sentry_dsn|sentry_clientside_dsn)[\s:="'']+https?://([A-Za-z0-9]{32})@'
category: auth_token
label: gitlab_sentry_key
- kind: allow
values:
- "gitlab"
- "gitlab.com"
- "gitlab.example.com"
- "gitlab-ci"
- "gitlab-ci.yml"
- ".gitlab-ci.yml"
- "gitlab-runner"
- "gitlab-org"
- "gitlab-ce"
- "gitlab-ee"
- "true"
- "false"
- "yes"
- "no"
- "null"
- "none"
- "nil"
- "0"
- "1"
- "localhost"
- "127.0.0.1"
- "0.0.0.0"
- "::1"
- "token"
- "secret"
- "password"
- "YOUR-*"
- "GENERATED_*"
- "YOUR_*"
- "CHANGE_*"
- "REPLACE_*"
- "ENTER_*"
- "<*>"
- "changeme"
- "example"
- "sample"
- "placeholder"
- "${*}"
- "{{*}}"
- "example.com"
- "example.org"