Files
mattandCursor ce7b2b838c fix(detectors/ngrok): broaden valid bearer tokens matching (#5152)
* fix(detectors/ngrok): match API keys that do not start with 2

The ngrok bearer token pattern is 27 alphanumerics, an underscore, and 21
alphanumerics. Requiring a leading 2 missed valid API keys and ak_ resource
IDs were never secrets.

Co-authored-by: Cursor <[email protected]>

* fix(detectors/ngrok): restore digit-leading suffix constraint

The prefix broadening accidentally allowed any alphanumeric suffix start, which would increase false positives.

Co-authored-by: Cursor <[email protected]>

* fix(detectors/ngrok): accept 20-21 char suffixes with any leading char

Real authtokens verified against the ngrok API can have 20-char and
letter-leading suffixes, so the digit-leading 21-char suffix constraint
drops valid secrets.

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-09-14 14:16:40 -04:00
..