Watch
2
trufflehog catalog hook scans gitignored target/ in Rust consumers, blocks every commit #288
Closed
opened 2026-06-25 11:23:05 +00:00 by coilysiren
·
5 comments
No Branch/Tag specified
main
release
aos/claude/md68
aos/claude/zc49-creature-numbers
aos/claude/zc49-creature-background
chore/full-name-attribution
aos/claude/mt75-bundle-tag
aos/claude/ad84-revert-voice
aos/claude/ad84-voice
aos/claude/tc69-abspath
aos/claude/mt75-quiet-plan
voice-no-rarity-statements
aos/claude/mt75-netlify-remove
aos/claude/ad84-titles
aos/claude/ad84
aos/claude/mt75-aterm-fullscreen
aos/claude/mt75-netlify-wrap
aos/claude/mt75-kubectl-context
aos/claude/mt75
aos/claude/mt75-ward-cut
aos/claude/eb77
aos/claude/fp87-ward-schema
aos/claude/fp87-ward-posture
aos/claude/fp87
aos/claude/vt77
aos/1105-require-issue-labels
aos/claude/kb87-native-arch
aos/claude/kb87-window-identity
aos/claude/kb87
aos/claude/tg69
aos/claude/ff54-retire-issue-refs
aos/claude/ff54
aos/claude/rc44-bundle-version
aos/claude/mu55-contract-tests
aos/claude/mu55-sound-mark
aos/claude/rc44
aos/claude/mu55-identity-card
aos/claude/mu55-doctor
aos/claude/mu55-shadow-reap
aos/claude/mu55-drop-windows
aos/claude/mu55-dryrun-exits
aos/claude/mu55-list-json
aos/claude/mu55-title-order
aos/claude/mu55-overlay-contract
aos/claude/qu74
aos/claude/ue86
aos/claude/yq86
aos/claude/vk48-harness-set
aos/claude/vk48-default-agent
aos/claude/vk48-completion
aos/claude/vk48-release-fix
aos/claude/vk48
aos/claude/yb89
aos/claude/sb46
fix/agent-compose-pin-v3-roster
aos/claude/ve67-defer
aos/claude/ve67
aos/claude/ur54
aos/claude/tj49
feat/acompose-v3-roster
ops/393-retire-doc-size-alias
ops/393-drop-em-dash-check
feat/vendored-tree-exclude
aos/claude/xlarge-band
aos/claude/ue65
aos/claude/identity-color-wins
aos/claude/ap47
aos/claude/zr44
aos/claude/xk58
aos/claude/aw85-skill-size-owner
aos/claude/ym96-docs-bands
aos/claude/wt57-pin-aos-bundle
aos/claude/wt57-image-inputs-filter
aos/claude/ym96-label-taxonomy
ops/dev-base-pin-rust-1.90.0
aos/claude/mg96-clean
aos/claude/mg96
backup/fix/bake-precommit-hooks
rescue/aos-test-timeout
aos/claude/issues-977-979-agents-base
aos/claude/sx87
refactor/remove-context-budget-json
issue-946
aos/codex/20260806t050901z-50407-6291ab0a
aos/codex/standalone-shadow-workspace
backup/aos/codex/20260806t061240z-10127-754d7de2
aos/codex/standalone-local-service-route
aos/codex/aosterm-aoscompose-wrapper
aos/codex/agents-launch-profile-source
aos/codex/launch-profiles-yaml
aos/codex/20260806t031603z-7731-c76c17f2
backup/aos/codex/20260805t183628z-5916-617bb239
backup/aos/codex/20260805t025242z-30811-fbb135ff
aos/codex/aos-v2-roster-852
aos/codex/20260801t164712z-64119-69ee8bb6
backup/aos/codex/20260801t164900z-67616-2ad2d0e3
issue-834
aos/codex/pr-829-1130
issue-824-agent-proxy-model-routing
task-merge-pr818
fix/aos-ci-20260730
issue-671
issue-734
issue-484
issue-498
issue-622
issue-512
issue-679
issue-454
backup/issue-785-first-person
issue-785-first-person
director-pr784
restore-language-images
recovery/2026-07-28-triaged-branch-archive
recovery/2026-07-27-local-work
recovery/aos-local-build-20260727
codex/land-pr-733
codex/aos-ci-watch
issue-642
issue-682-goose-yaml
issue-656-goose-context
safety/aos-local-main-09347d0
issue-611-specialist-images
fix-action-run-list-page
issue-454-v2
experiment/no-ops-forgejo
feat/dev-base-image
aos-v0.278.0
aos-v0.277.0
aos-v0.276.0
aos-v0.275.0
v0.283.0
aos-v0.274.0
aos-precommit-v0.63.0
aos-v0.273.0
aos-v0.272.0
aos-precommit-v0.62.0
aos-v0.271.0
aos-v0.270.0
aos-precommit-v0.61.0
aos-precommit-v0.60.0
aos-v0.269.0
aos-v0.268.0
aos-precommit-v0.59.0
aos-precommit-v0.58.0
aos-v0.267.0
aos-precommit-v0.57.0
aos-precommit-v0.56.0
aos-eval-v0.12.0
aos-v0.266.0
aos-eval-v0.11.0
aos-eval-v0.10.0
aos-precommit-v0.55.0
aos-v0.265.0
aos-v0.264.0
aos-v0.263.0
aos-v0.262.0
aos-eval-v0.9.0
aos-v0.261.0
aos-v0.260.0
aos-v0.259.0
aos-v0.258.0
aos-v0.257.0
aos-precommit-v0.54.0
aos-precommit-v0.53.0
aos-precommit-v0.52.0
aos-precommit-v0.51.0
aos-precommit-v0.50.0
v0.282.0
v0.281.0
aos-v0.256.0
aos-v0.255.0
aos-v0.254.0
aos-v0.253.0
aos-v0.252.0
aos-v0.251.0
aos-v0.250.0
aos-v0.249.0
aos-v0.248.0
aos-v0.247.0
aos-v0.246.0
aos-v0.245.0
aos-v0.244.0
aos-v0.243.0
aos-v0.242.0
aos-v0.241.0
v0.280.0
aos-v0.240.0
aos-v0.239.0
aos-v0.238.0
aos-v0.237.0
aos-v0.236.0
aos-v0.235.0
aos-v0.234.0
aos-v0.233.0
aos-v0.232.0
aos-v0.231.0
aos-v0.230.0
aos-v0.229.0
aos-v0.228.0
aos-v0.227.0
v0.279.0
aos-v0.226.0
v0.278.0
aos-v0.224.0
aos-v0.223.0
v0.277.0
aos-precommit-v0.49.0
aos-v0.222.0
aos-precommit-v0.48.0
aos-eval-v0.8.0
aos-eval-v0.7.0
v0.276.0
aos-precommit-v0.47.0
aos-precommit-v0.46.0
aos-v0.221.0
aos-precommit-v0.45.0
aos-v0.220.0
aos-eval-v0.6.0
aos-precommit-v0.44.0
aos-v0.219.0
aos-v0.218.0
v0.275.0
aos-precommit-v0.43.0
aos-v0.217.0
aos-precommit-v0.42.0
aos-precommit-v0.41.0
aos-eval-v0.5.0
aos-precommit-v0.40.0
aos-precommit-v0.39.0
aos-v0.216.0
aos-precommit-v0.38.0
aos-precommit-v0.37.0
aos-precommit-v0.36.0
aos-v0.215.0
aos-precommit-v0.35.0
aos-v0.214.0
aos-precommit-v0.34.0
aos-precommit-v0.33.0
aos-precommit-v0.32.0
aos-precommit-v0.31.0
v0.274.0
aos-eval-v0.4.0
aos-eval-v0.3.0
aos-precommit-v0.30.0
aos-precommit-v0.29.0
aos-precommit-v0.28.0
aos-precommit-v0.27.0
aos-eval-v0.2.0
aos-precommit-v0.26.0
aos-eval-v0.1.0
aos-precommit-v0.25.0
aos-precommit-v0.24.0
aos-v0.213.0
aos-v0.212.0
aos-v0.211.0
aos-v0.210.0
aos-v0.209.0
aos-v0.208.0
aos-v0.207.0
aos-v0.206.0
aos-v0.205.0
aos-v0.204.0
aos-v0.203.0
aos-precommit-v0.23.0
v0.273.0
v0.272.0
aos-v0.202.0
aos-precommit-v0.22.0
v0.271.0
aos-v0.201.0
aos-v0.200.0
aos-precommit-v0.21.0
aos-v0.199.0
aos-v0.198.0
aos-precommit-v0.20.0
v0.270.0
aos-precommit-v0.19.0
aos-v0.197.0
aos-v0.196.0
v0.269.0
aos-v0.195.0
aos-v0.194.0
aos-v0.193.0
aos-precommit-v0.18.0
v0.268.0
v0.267.0
aos-precommit-v0.17.0
v0.266.0
aos-v0.192.0
aos-v0.191.0
aos-precommit-v0.16.0
aos-v0.190.0
aos-v0.189.0
aos-v0.188.0
aos-v0.187.0
aos-v0.186.0
aos-precommit-v0.15.0
aos-v0.185.0
aos-v0.184.0
aos-precommit-v0.14.0
aos-v0.183.0
v0.265.0
aos-v0.182.0
aos-v0.181.0
aos-v0.180.0
aos-v0.179.0
aos-precommit-v0.13.0
aos-v0.178.0
aos-precommit-v0.12.0
aos-v0.177.0
aos-precommit-v0.11.0
aos-v0.176.0
aos-v0.175.0
aos-v0.174.0
aos-precommit-v0.10.0
aos-v0.173.0
aos-v0.172.0
aos-v0.171.0
aos-v0.170.0
aos-v0.169.0
aos-v0.168.0
aos-v0.167.0
aos-precommit-v0.9.0
v0.264.0
aos-v0.166.0
aos-v0.165.0
aos-v0.164.0
aos-v0.163.0
aos-v0.162.0
aos-v0.161.0
v0.263.0
aos-v0.160.0
aos-v0.159.0
aos-precommit-v0.8.0
aos-v0.158.0
aos-v0.157.0
aos-precommit-v0.7.0
aos-v0.156.0
aos-v0.155.0
aos-v0.154.0
aos-v0.153.0
v0.262.0
aos-precommit-v0.6.0
aos-precommit-v0.5.0
aos-precommit-v0.4.0
aos-v0.152.0
aos-precommit-v0.3.0
aos-v0.151.0
aos-v0.150.0
aos-v0.149.0
aos-precommit-v0.2.0
aos-v0.148.0
aos-v0.147.0
aos-v0.146.0
aos-v0.145.0
aos-v0.144.0
aos-v0.143.0
aos-precommit-v0.1.0
aos-v0.142.0
aos-v0.141.0
aos-v0.140.0
aos-v0.139.0
aos-v0.138.0
aos-v0.137.0
aos-v0.136.0
aos-v0.135.0
aos-v0.134.0
aos-v0.133.0
aos-v0.132.0
aos-v0.131.0
aos-v0.130.0
aos-v0.129.0
aos-v0.128.0
aos-v0.127.0
aos-v0.126.0
aos-v0.125.0
v0.261.0
aos-v0.124.0
v0.260.0
aos-v0.123.0
aos-v0.122.0
aos-v0.121.0
aos-v0.120.0
aos-v0.119.0
aos-v0.118.0
aos-v0.117.0
aos-v0.116.0
aos-v0.115.0
aos-v0.114.0
aos-v0.113.0
aos-v0.112.0
aos-v0.111.0
aos-v0.110.0
aos-v0.109.0
aos-v0.108.0
aos-v0.107.0
aos-v0.106.0
aos-v0.105.0
aos-v0.104.0
v0.259.0
aos-v0.103.0
v0.258.0
aos-v0.102.0
aos-v0.101.0
aos-v0.100.0
aos-v0.99.0
aos-v0.98.0
aos-v0.97.0
aos-v0.96.0
aos-v0.95.0
aos-v0.94.0
aos-v0.93.0
aos-v0.92.0
aos-v0.91.0
aos-v0.90.0
aos-v0.89.0
v0.257.0
aos-v0.88.0
aos-v0.87.0
aos-v0.86.0
v0.256.0
aos-v0.85.0
aos-v0.84.0
aos-v0.83.0
aos-v0.82.0
aos-v0.81.0
aos-v0.80.0
aos-v0.79.0
aos-v0.78.0
aos-v0.77.0
aos-v0.76.0
aos-v0.75.0
aos-v0.74.0
aos-v0.73.0
aos-v0.72.0
aos-v0.71.0
aos-v0.70.0
aos-v0.69.0
aos-v0.68.0
aos-v0.67.0
aos-v0.66.0
aos-v0.65.0
aos-v0.64.0
aos-v0.63.0
aos-v0.62.0
aos-v0.61.0
aos-v0.60.0
aos-v0.59.0
aos-v0.58.0
aos-v0.57.0
aos-v0.56.0
aos-v0.55.0
aos-v0.54.0
aos-v0.53.0
aos-v0.52.0
aos-v0.51.0
aos-v0.50.0
aos-v0.49.0
aos-v0.48.0
aos-v0.47.0
aos-v0.46.0
aos-v0.45.0
aos-v0.44.0
aos-v0.43.0
aos-v0.42.0
aos-v0.41.0
aos-v0.40.0
aos-v0.39.0
aos-v0.38.0
aos-v0.37.0
aos-v0.36.0
aos-v0.35.0
aos-v0.34.0
aos-v0.33.0
aos-v0.32.0
aos-v0.31.0
aos-v0.30.0
aos-v0.29.0
aos-v0.28.0
aos-v0.27.0
aos-v0.26.0
aos-v0.25.0
aos-v0.24.0
aos-v0.23.0
aos-v0.22.0
aos-v0.21.0
aos-v0.20.0
aos-v0.19.0
aos-v0.18.0
aos-v0.17.0
aos-v0.16.0
aos-v0.15.0
aos-v0.14.0
aos-v0.13.0
aos-v0.12.0
aos-v0.11.0
aos-v0.10.0
aos-v0.9.0
aos-v0.8.0
aos-v0.7.0
aos-v0.6.0
aos-v0.5.0
aos-v0.4.0
aos-v0.3.0
aos-v0.2.0
aos-v0.1.0
v0.255.0
v0.254.0
v0.253.0
v0.252.0
v0.251.0
v0.250.0
v0.249.0
v0.248.0
v0.247.0
v0.246.0
v0.245.0
v0.244.0
v0.243.0
v0.242.0
v0.241.0
v0.240.0
v0.239.0
v0.238.0
v0.237.0
v0.236.0
v0.235.0
v0.234.0
v0.233.0
v0.232.0
v0.231.0
v0.230.0
v0.229.0
v0.228.0
v0.227.0
v0.226.0
v0.225.0
v0.224.0
v0.223.0
v0.222.0
v0.221.0
v0.220.0
v0.219.0
v0.218.0
v0.217.0
v0.216.0
v0.215.0
v0.214.0
v0.213.0
v0.212.0
v0.211.0
v0.210.0
v0.209.0
v0.208.0
v0.207.0
v0.206.0
v0.205.0
v0.204.0
v0.203.0
v0.202.0
v0.201.0
v0.200.0
v0.199.0
v0.198.0
v0.197.0
v0.196.0
v0.195.0
v0.194.0
v0.193.0
v0.192.0
v0.191.0
v0.190.0
v0.189.0
v0.188.0
v0.187.0
v0.186.0
v0.185.0
v0.184.0
v0.183.0
v0.182.0
v0.181.0
v0.180.0
v0.179.0
v0.178.0
v0.177.0
v0.176.0
v0.175.0
v0.174.0
v0.173.0
v0.172.0
v0.171.0
v0.170.0
v0.169.0
v0.168.0
v0.167.0
v0.166.0
v0.165.0
v0.164.0
v0.163.0
v0.162.0
v0.161.0
v0.160.0
v0.159.0
v0.158.0
v0.157.0
v0.156.0
v0.155.0
v0.154.0
v0.153.0
v0.152.0
v0.151.0
v0.150.0
v0.149.0
v0.148.0
v0.147.0
v0.146.0
v0.145.0
v0.144.0
v0.143.0
v0.142.0
v0.141.0
v0.140.0
v0.139.0
v0.138.0
v0.137.0
v0.136.0
v0.135.0
v0.134.0
v0.133.0
v0.132.0
v0.131.0
v0.130.0
v0.129.0
v0.128.0
v0.127.0
v0.126.0
v0.125.0
v0.124.0
v0.123.0
v0.122.0
v0.121.0
v0.120.0
v0.119.0
v0.118.0
v0.117.0
v0.116.0
v0.115.0
v0.114.0
v0.113.0
v0.112.0
v0.111.0
v0.110.0
v0.109.0
v0.108.0
v0.107.0
v0.106.0
v0.105.0
v0.104.0
v0.103.0
v0.102.0
v0.101.0
v0.100.0
v0.99.0
v0.98.0
v0.97.0
v0.96.0
v0.95.0
v0.94.0
v0.93.0
v0.92.0
v0.91.0
v0.90.0
v0.89.0
v0.88.0
v0.87.0
v0.86.0
v0.85.0
v0.84.0
v0.83.0
v0.82.0
v0.81.0
v0.80.0
v0.79.0
v0.78.0
v0.77.0
v0.76.0
v0.75.0
v0.74.0
v0.73.0
v0.72.0
v0.71.0
v0.70.0
v0.69.0
v0.68.0
v0.67.0
v0.66.0
v0.65.0
v0.64.0
v0.63.0
v0.62.0
v0.61.0
v0.60.0
v0.59.0
v0.58.0
v0.57.0
v0.56.0
v0.55.0
v0.54.0
v0.53.0
v0.52.0
v0.51.0
v0.50.0
v0.49.0
v0.48.0
v0.47.0
v0.46.0
v0.45.0
v0.44.0
v0.43.0
v0.42.0
v0.41.0
v0.40.0
v0.39.0
v0.38.0
v0.37.0
v0.36.0
v0.35.0
v0.34.0
v0.33.0
v0.32.0
v0.31.0
v0.30.0
v0.29.0
v0.28.0
v0.27.0
v0.26.0
v0.25.0
v0.24.0
v0.23.0
v0.22.0
v0.21.0
v0.20.0
v0.19.0
v0.18.0
v0.17.0
v0.16.0
v0.15.0
v0.14.0
v0.13.1
v0.13.0
v0.12.0
v0.11.1
v0.11.0
v0.10.0
v0.9.0
v0.8.0
v0.7.0
v0.6.0
v0.5.0
v0.4.0
v0.3.0
v0.2.12
v0.2.11
v0.2.10
v0.2.9
v0.2.8
v0.2.7
v0.2.6
v0.2.5
v0.2.4
v0.2.3
v0.2.2
v0.2.1
v0.2.0
v0.1.0
Labels
Clear labels
burndown-2026-06
Backlog burndown June 2026
burndown-2026-08
Closed in the 2026-08-26 backlog burn-down. Reopen freely: state:closed label:burndown-2026-08 recovers the whole set.
autonomy
async-consult
A human needs to consult on the issue to upgrade it to headless
autonomy
epic
This issue has many units of sub work - its size makes it meaningfully exclusive with other autonomy types
autonomy
headless
The agent can perform the work on its own
autonomy
live-collab
The agent and the human need to work together in realtime
coherence-core
Core review set for the warded control plane coherence milestone. These issues form the release spine; adjacent milestone issues are stretch or supporting work.
priority
P0
priority tier
priority
P1
priority tier
priority
P2
priority tier
priority
P3
priority tier
priority
P4
priority tier
qa-fixture
Disposable issue admitted to the bounded Ward QA verification lane.
role/advocate
requires work from the Developer Advocate seat
role/director
requires work from the Portfolio Director seat
role/exec
requires work from the exec role
role/frontend
requires work from the Frontend Engineer seat
role/gamedev
requires work from the Game Developer seat
role/human
requires a person, and specifically not an agent seat
role/platform
requires work from the Platform Engineer seat
role/qa
requires work from the QA role
role/science
requires work from the Applied Scientist seat
role/sysadmin
requires work from the Systems Administrator seat
state
ambient
ambient and ephemeral work, held as a maintained document rather than a queue
No labels
burndown-2026-06
burndown-2026-08
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/advocate
role/director
role/exec
role/frontend
role/gamedev
role/human
role/platform
role/qa
role/science
role/sysadmin
state
ambient
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/agentic-os#288
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
The catalog
trufflehog (secret scan, offline)hook shipped from this repo(
.pre-commit-hooks.yaml) false-positives on Rust build artifacts. On any hostthat has run a release build,
target/exists (gitignored, untracked) and thehook reads its binary blobs (
libzerocopy-*.rlib,.rmeta,*.pdb), emittingthousands of bogus "unverified" hits that block every
git commit.Reported in coilyco-bridge/agentic-os-kai#530. It blocked landing the
.forgejo/migration in
coilysiren/repo-recallon a tower untilrm -rf target/(4.6GB,fully reproducible). It affects every Rust-shaped consumer of this hook
(repo-recall, cli-guard, ward, coily).
Current hook entry
.pre-commit-hooks.yaml, idtrufflehog:Root cause
trufflehog's
git file://.scan reads the working copy, and for untracked filesit does not consult
.gitignore(upstream feature request trufflesecurity/trufflehog#3356confirms trufflehog does not honor
.gitignore). So gitignoredtarget/getswalked. Removing
target/is what clears the hits, which proves the working-treeread is the source.
Fix shape (verify empirically with a live trufflehog before landing)
This repo is the right home because the entry is centrally managed: consumers
carry it via the
apply-agentic-os-hooks.pymanaged block, and that block isregenerated with no per-hook args, so a consumer-side override does not survive.
Candidates, in rough order of preference:
--exclude-globsappended inline (travels with the shared entry, no per-repofile needed): e.g.
--exclude-globs 'target/**,dist/**,build/**,node_modules/**'.Caveat to verify:
--exclude-globsis documented as filtering at thegit loglevel, so confirm it also suppresses the untracked working-tree read, not just
committed objects.
--exclude-paths <file>of regexes (the pattern already used inagentic-os-kai's
.github/workflows/trufflehog.ymlCI scan:(^|/)target/,\.venv/,node_modules/, the cache dirs). Downside: needs a committedregex file each consumer carries, awkward for a shared entry.
The carrying agent should reproduce with
cargo build --release+ an emptycommit, pick whichever flag actually suppresses the working-tree read, and keep
real staged-secret detection intact (do not blanket
--only-verified, the hookis offline
--no-verification).Rollout (part of done)
Landing the entry change is not enough on its own. Consumers pin a
rev:, soafter this lands and a release tag cuts, bump the pin fleet-wide via
make apply-agentic-os-hooks/apply-agentic-os-hooks.py --rev vXso Rustrepos actually receive the fix. Closing agentic-os-kai#530 depends on that
rollout reaching the affected repos.
Repro
Filed from the agentic-os-kai#530 carry container, which is scoped to
agentic-os-kai and cannot push this repo. Cross-ref: coilyco-bridge/agentic-os-kai#530.
Carry-readiness notes (from the agentic-os-kai#530 re-dispatch)
Re-confirmed this from a kai-scoped carry container and pinned down the open empirical question as far as docs allow, so whoever carries this lands a near-mechanical diff.
Why the working-tree read happens (mechanism). trufflehog's
git file://.source scans the working-tree state (staged + unstaged + untracked) as a synthetic diff against HEAD - that is precisely why it works as a pre-commit hook, catching secrets before they are committed. It does not honor.gitignorefor those untracked files (upstream trufflesecurity/trufflehog#3356). So gitignored-but-untrackedtarget/blobs get walked.--since-commit HEADdoes not change this - the working-tree synthetic diff is independent of the commit range.Generator confirmed to wipe consumer-side args.
apply-agentic-os-hooks.py:180stamps bare- id: {h}lines with no args, so anyargs:an affected repo adds to its managed block is erased on the next rollout. Confirms this repo is the only durable home.Flag recommendation, in order:
--exclude-paths=<file>is the documented path-regex filter for the git source (one regex per line, matched against object paths). It is the same approach already proven in agentic-os-kai's own.github/workflows/trufflehog.yml. Proven regex set to reuse:(^|/)target/,(^|/)\.venv/,(^|/)venv/,(^|/)node_modules/,(^|/)__pycache__/,(^|/)\.mypy_cache/,(^|/)\.pytest_cache/,(^|/)\.ruff_cache/- add(^|/)(dist|build)/for Rust/JS artifacts. Downside unchanged: needs a committed regex file in every consumer, awkward for a single shared entry.--exclude-globs 'target/**,dist/**,build/**,node_modules/**'is inline (no per-consumer file) and is the cleaner shape if it covers the untracked working-tree read. That coverage is undocumented for the git source - docs describe--exclude-globsat thegit loglevel. This is the one thing that still needs a live trufflehog against a realtarget/to confirm before landing.Carry environment requirement. The verify step needs the trufflehog binary plus a populated
target/(cargo build --releasein a Rust consumer, then an empty commit). The kai-scoped container has neither (Python repo, no binary), which is why this cannot be verified from there. Carry this in a container that grants this repo and has trufflehog on PATH.Rollout is part of done: land entry change -> release tag cuts -> bump
rev:fleet-wide viaapply-agentic-os-hooks.py --rev vX. agentic-os-kai#530 stays open until the rollout reaches the Rust consumers (repo-recall, cli-guard, ward, coily).Cross-ref: coilyco-bridge/agentic-os-kai#530.
🔒 Reserved by
ward agent --driver claude— containerengineer-claude-agentic-os-288on hostkais-macbook-pro-2.localis carrying this issue (reserved 2026-07-01T04:36:43Z). Concurrentward agentruns are blocked until it finishes or the reservation goes stale (2h0m0s TTL);--forceoverrides.— Claude (she/her), via
ward agentWARD-OUTCOME: done - trufflehog catalog hook now excludes gitignored build/cache dirs via scripts/trufflehog-scan.sh (--exclude-paths), landed on main
d4ef2bb.The interesting part was that the bug did not reproduce against the shipped trufflehog (3.95.7): its
git file://.source only scans committed history plus the staged index, and never touches the untracked gitignoredtarget/. So the reported flood must come from an older trufflehog whose synthetic working-tree diff included untracked files. That reframed the job from "reproduce and fix" to "make the shared entry robust across the version that does the untracked read."What fought back was the flag choice. The issue's preferred candidate, inline
--exclude-globs, turned out to be the wrong tool: I staged a secret insidetarget/and--exclude-globs 'target/**'did NOT drop it - it only filters committed git-log objects, not the synthetic working/staged diff.--exclude-paths(a regex file) DID filter that diff by path while keeping a real leak outside the excluded dirs failing. That empirical split is the whole reason for the shape that landed.To dodge the "every consumer carries an exclude file" downside I moved the entry to
language: scriptpointing at a wrapper committed here, so the regex list ships centrally through the pre-commit cache. Verified end to end withpre-commit try-repo: gitignoredtarget/full of secrets passes, a real staged secret fails. Confidence is high on correctness.One rough edge worth flagging: the fix is version-robust but I could not exercise the actual untracked-read path, since no old-enough trufflehog was on hand - I proved
--exclude-pathsfilters the same synthetic-diff mechanism the old read rode, which is strong but indirect. Follow-up, and the real closer for agentic-os-kai#530: after this release tag cuts, the fleetrev:pin still needs bumping on the Rust consumers (repo-recall, cli-guard, ward, coily). That rollout is a host/ansible step outside this container's grant, so #530 should stay open until it lands there.🔒 Reserved by
ward agent --driver claude— containerengineer-claude-agentic-os-288on hostkais-macbook-pro-2.localis carrying this issue (reserved 2026-07-01T07:04:27Z). Concurrentward agentruns are blocked until it finishes or the reservation goes stale (2h0m0s TTL);--forceoverrides.— Claude (she/her), via
ward agentWARD-OUTCOME: done - trufflehog wrapper (scripts/trufflehog-scan.sh, --exclude-paths) already landed on main
d4ef2bbclosing #288; I independently re-verified it end to end.Candid note: I came up to a fully-carried issue. A prior container (linux-0c646...cc47) had already implemented the wrapper, pushed
d4ef2bbstraight to canonical main, closed the issue, and left its own done retrospective. My HEAD was already sitting exactly on that commit, so there was no feature left to build - the honest job was to re-verify rather than re-do.What I checked, and where it fought back a little: my first "real staged secret still fails" test came back green (exit 0) and briefly worried me, until I realized I'd used
AKIA...EXAMPLE, which is trufflehog's own blessed placeholder that detectors deliberately ignore. Swapping in a genuinely detectable token flipped it to a proper failure (exit 183), while the same token confined to a gitignoredtarget/passed clean. So the two load-bearing behaviors both hold: real staged leaks still block, gitignored build dirs don't. shellcheck passes on the wrapper and the full suite is green at HEAD.Confidence: high on correctness of what landed. The one honest caveat carries over from the original carry - trufflehog 3.95.7 doesn't walk untracked
target/anyway, so the exclude is proven against the synthetic-diff mechanism but not against the actual old-version untracked read that triggered the report. Follow-up unchanged and real: this only reaches the Rust consumers after a release tag cuts and the fleetrev:pin is bumped (apply-agentic-os-hooks.py --rev vX), which is a host/ansible step outside this container. agentic-os-kai#530 should stay open until that rollout lands.