rules:
  - id: auth.secret.provider-key
    languages:
      - javascript
      - typescript
    severity: ERROR
    message: |
      A hard-coded credential matching a well-known provider's key format
      was found in the source. These keys are designed to be revocable.
      Once one ships to git, the only safe action is to rotate it, even
      if the repo is private.

      Move the value to an environment variable, a secret manager (AWS
      Secrets Manager, GCP Secret Manager, Doppler, 1Password CLI),
      or a `.env` file that's `.gitignore`d.

      Detected formats:
        - Stripe live / test:  sk_live_…  / sk_test_…   / pk_live_…
        - OpenAI:              sk-…  /  sk-proj-…
        - Anthropic:           sk-ant-…
        - GitHub:              ghp_… / gho_… / ghu_… / ghs_… / ghr_… / github_pat_…
        - Google Workspace:    GOCSPX-…
        - Google API key:      AIza…
        - AWS Access Key:      AKIA[0-9A-Z]{16}
        - Slack Bot / User:    xoxb-… / xoxp-…
    pattern-either:
      - pattern-regex: \b(?:sk|pk|rk)_(?:live|test)_[0-9a-zA-Z]{16,}
      - pattern-regex: \bsk-(?:ant-|proj-)?[A-Za-z0-9_-]{20,}
      - pattern-regex: \bgh[opusr]_[A-Za-z0-9]{36,}
      - pattern-regex: \bgithub_pat_[A-Za-z0-9_]{40,}
      - pattern-regex: \bGOCSPX-[A-Za-z0-9_-]{20,}
      - pattern-regex: \bAKIA[0-9A-Z]{16}\b
      - pattern-regex: \bAIza[0-9A-Za-z_-]{35}\b
      - pattern-regex: \bxox[bp]-[0-9]{10,}-[0-9]{10,}-[A-Za-z0-9]{20,}
    metadata:
      oauthlint-rule-id: AUTH-SECRET-001
      oauthlint-doc-url: https://oauthlint.dev/rules/secret-provider-key
      category: security
      cwe: CWE-798
      owasp: API8:2023
      llm-prevalence: HIGH
      references:
        - https://blog.gitguardian.com/the-state-of-secrets-sprawl-2026/
        - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/
