* fix(detectors/ngrok): match API keys that do not start with 2
The ngrok bearer token pattern is 27 alphanumerics, an underscore, and 21
alphanumerics. Requiring a leading 2 missed valid API keys and ak_ resource
IDs were never secrets.
Co-authored-by: Cursor <[email protected]>
* fix(detectors/ngrok): restore digit-leading suffix constraint
The prefix broadening accidentally allowed any alphanumeric suffix start, which would increase false positives.
Co-authored-by: Cursor <[email protected]>
* fix(detectors/ngrok): accept 20-21 char suffixes with any leading char
Real authtokens verified against the ngrok API can have 20-char and
letter-leading suffixes, so the digit-leading 21-char suffix constraint
drops valid secrets.
Co-authored-by: Cursor <[email protected]>
---------
Co-authored-by: Cursor <[email protected]>