Repository navigation
Conversation
Pinecone (pcsk_) keys grant access to vector-database indexes backing RAG/AI apps; LangSmith (lsv2_pt_ / lsv2_sk_) keys expose LangChain/LangSmith tracing data, prompts, and connected LLM workloads. Both are increasingly committed to source in the LLM/RAG ecosystem and were undetected by gitleaks. Adds pinecone-api-key and langsmith-api-key rules with prefix-anchored regexes, keyword prefilters, entropy 3, and TP/FP validation samples; regenerated config/gitleaks.toml via go generate. Signed-off-by: Devam Shah <devamshah91@gmail.com>
sanmaxdev
left a comment
There was a problem hiding this comment.
Both rules look solid. The Pinecone regex (pcsk_[A-Za-z0-9]{5,6}_[A-Za-z0-9]{63}) and LangSmith regex (lsv2_(?:pt|sk)_[a-z0-9]{32}_[a-z0-9]{10}) match their documented key formats, and the false positive cases (wrong prefix, wrong key-type segment, too-short body) are covered.
Verified:
go run ./cmd/generate/config/main.go ../../../config/gitleaks.toml(config regenerates with no diff)go test ./detect/... -count=1go build ./...
|
Re-verified this against current Still applies cleanly. What I ran on top of The End-to-end check with the built binary, not just the That covers both the 5- and 6-character Pinecone id segment ( On why this is
@sanmaxdev — thanks for actually running the generator and the tests back in July rather than eyeballing the regex. Is there anything else you want changed here, or is this purely waiting on maintainer bandwidth? If a maintainer would rather I split Pinecone and LangSmith into two separate PRs to make review smaller, I'll do that today. |
Summary
Adds two new high-confidence Gitleaks rules —
pinecone-api-keyandlangsmith-api-key— covering credentials for the vector-database and LLM-observability layers that now sit at the centre of most RAG/AI stacks. Both rules anchor on vendor-issued, structurally distinctive prefixes, so they detect real leaks while keeping false positives near zero.Problem / motivation
Gitleaks ships rules for the AI model providers (Anthropic, OpenAI, Cohere, Hugging Face, Perplexity, Bedrock) but has no coverage for the retrieval and observability tier those models depend on. A leaked Pinecone or LangSmith key is not a low-value finding:
Both are routinely committed to
.envfiles, notebooks, CI config, and IaC, and today pass through Gitleaks undetected (at best they trip the noisygeneric-api-keyrule, which yields a generic finding with no provenance).Change
Following
CONTRIBUTING.mdexactly:cmd/generate/config/rules/pinecone.go—PineconeApiKey()cmd/generate/config/rules/langsmith.go—LangsmithApiKey()cmd/generate/config/main.go(alphabetical ordering preserved).config/gitleaks.tomlviago generate ./cmd/generate/config/.Both rules use
GenerateUniqueTokenRegex, consistent with the existing prefix-anchored AI-provider rules (anthropic.go,openai.go), because the token prefixes are themselves the high-signal identifier:pinecone-api-keypcsk_[A-Za-z0-9]{5,6}_[A-Za-z0-9]{63}pcsk_<label>_<key>formatlangsmith-api-keylsv2_(?:pt|sk)_[a-z0-9]{32}_[a-z0-9]{10}lsv2_pt_) and service-key (lsv2_sk_) prefixes per LangSmith admin docsAn
entropy = 3floor is set on both to suppress low-entropy placeholders and documentation samples.Security rationale
Testing / validation
go generate ./cmd/generate/config/— succeeds; the generator runsValidate()(true-positive + false-positive assertions) against every rule and exits non-zero on any failure. Both new rules pass.go build ./...— clean.go test ./cmd/generate/... ./config/...— pass (theconfigtest parses the regeneratedgitleaks.toml).gitleaks detectagainst a fixture:pcsk_<6>_<63>,lsv2_pt_<32>_<10>,lsv2_sk_<32>_<10>— each attributed to the correct rule.pcsk_abc_tooshort, a genericeyJ...JWT, a legacyls__key (deprecated 2024-10-22), and a malformedlsv2_xx_...type segment.Checklist
gofmt)