{"_id":"@dnbhq/secretlint-config","_rev":"2-0315b5decd57af53770582cb97aa91d7","name":"@dnbhq/secretlint-config","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@dnbhq/secretlint-config","version":"0.1.0","keywords":["secretlint","secrets","linting","config","dnbhq"],"author":{"url":"https://davids-neighbour.com","name":"Patrick Kollitsch","email":"davidsneighbourdev+gh@gmail.com"},"license":"MIT","_id":"@dnbhq/secretlint-config@0.1.0","maintainers":[{"name":"davidsneighbour","email":"pkollitsch@gmail.com"}],"homepage":"https://github.com/dnbhq/secretlint-config#readme","bugs":{"url":"https://github.com/dnbhq/secretlint-config/issues"},"bin":{"dnb-secretlint":"bin/dnb-secretlint.js"},"dist":{"shasum":"725eaa3624d60c35ed5a53ff5f213d4a9502317d","tarball":"https://registry.npmjs.org/@dnbhq/secretlint-config/-/secretlint-config-0.1.0.tgz","fileCount":6,"integrity":"sha512-BscPyRwb31VHL1vfccZJ5HQnC/n7KtN8pmT9dLDX9z1ZtwZEIOmmYyVyKQ+3kkdsqNTvJqyRMpSsxWLOF/5Qsw==","signatures":[{"sig":"MEYCIQDo88oCtKHAsvMhnCJSDQ1xyO5GzueH50axzBhaAWyPYQIhAPwf8oi6hgsAEJ5VzZkP2a3PyEj6Dzy0P2z1cOa5+2Vp","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":13434},"type":"module","engines":{"node":">=22"},"exports":{".":"./config/index.js","./config":"./config/index.js","./secretlintrc":"./config/secretlintrc.json","./secretlintrc.json":"./config/secretlintrc.json"},"private":false,"scripts":{"lint":"npm run lint:code && npm run lint:markdown && npm run lint:secrets","test":"node --test","check":"npm run lint && npm run test && npm pack --dry-run","prepare":"simple-git-hooks","release":"release-it --ci","lint:code":"biome check .","lint:staged":"lint-staged","release:dry":"release-it --dry-run","test:config":"node --test test/config.test.js","lint:secrets":"node ./bin/dnb-secretlint.js README.md package.json bin/**/*.js config/**/*.js examples/**/*.js test/**/*.js .github/**/*.yml","lint:code:fix":"biome check --write .","lint:markdown":"markdownlint-cli2 --config ./node_modules/@dnbhq/markdownlint-config/.markdownlint-cli2.jsonc README.md","lint:markdown:fix":"markdownlint-cli2 --config ./node_modules/@dnbhq/markdownlint-config/.markdownlint-cli2.jsonc --fix README.md"},"_npmUser":{"name":"davidsneighbour","email":"pkollitsch@gmail.com"},"repository":{"url":"git+https://github.com/dnbhq/secretlint-config.git","type":"git"},"_npmVersion":"11.19.0","description":"Shared Secretlint configuration and CLI for DNBHQ projects.","directories":{},"lint-staged":{"*.{md,mdx}":"markdownlint-cli2 --config ./node_modules/@dnbhq/markdownlint-config/.markdownlint-cli2.jsonc --fix --no-globs","*.{js,json,jsonc,yml,yaml}":"biome check --write --no-errors-on-unmatched","*.{js,json,jsonc,md,mdx,yml,yaml,txt,cjs,mjs,ts,tsx}":"node ./bin/dnb-secretlint.js --no-glob"},"_nodeVersion":"26.8.1","dependencies":{"secretlint":"^13.0.4","@secretlint/secretlint-rule-preset-recommend":"^13.0.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"release-it":"21.0.0","lint-staged":"17.0.8","@biomejs/biome":"2.5.0","simple-git-hooks":"2.13.1","@dnbhq/biome-config":"0.2.3","@dnbhq/release-config":"1.1.3","@dnbhq/markdownlint-config":"0.2.11","@release-it/conventional-changelog":"12.0.0"},"simple-git-hooks":{"pre-commit":"npx lint-staged --allow-empty"},"_npmOperationalInternal":{"tmp":"tmp/secretlint-config_0.1.0_1787864464655_0.7755375863996625","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@dnbhq/secretlint-config","version":"0.1.1","description":"Shared Secretlint configuration and CLI for DNBHQ projects.","type":"module","license":"MIT","private":false,"author":{"name":"Patrick Kollitsch","email":"davidsneighbourdev+gh@gmail.com","url":"https://davids-neighbour.com"},"keywords":["secretlint","secrets","linting","config","dnbhq"],"engines":{"node":">=22"},"exports":{".":"./config/index.js","./config":"./config/index.js","./secretlintrc":"./config/secretlintrc.json","./secretlintrc.json":"./config/secretlintrc.json"},"bin":{"dnb-secretlint":"bin/dnb-secretlint.js"},"scripts":{"check":"npm run lint && npm run test && npm pack --dry-run","lint":"npm run lint:code && npm run lint:markdown && npm run lint:secrets","lint:code":"biome check .","lint:code:fix":"biome check --write .","lint:markdown":"markdownlint-cli2 --config ./node_modules/@dnbhq/markdownlint-config/.markdownlint-cli2.jsonc README.md","lint:markdown:fix":"markdownlint-cli2 --config ./node_modules/@dnbhq/markdownlint-config/.markdownlint-cli2.jsonc --fix README.md","lint:secrets":"node ./bin/dnb-secretlint.js README.md package.json bin/**/*.js config/**/*.js examples/**/*.js test/**/*.js .github/**/*.yml","lint:staged":"lint-staged","prepare":"simple-git-hooks","release":"release-it --ci","release:dry":"release-it --dry-run","test":"node --test","test:config":"node --test test/config.test.js"},"dependencies":{"@secretlint/secretlint-rule-preset-recommend":"^13.0.4","secretlint":"^13.0.4"},"devDependencies":{"@biomejs/biome":"2.5.0","@dnbhq/biome-config":"0.2.3","@dnbhq/markdownlint-config":"0.2.11","@dnbhq/release-config":"1.1.3","@release-it/conventional-changelog":"12.0.0","lint-staged":"17.0.8","release-it":"21.0.0","simple-git-hooks":"2.13.1"},"publishConfig":{"access":"public","provenance":true},"repository":{"type":"git","url":"git+https://github.com/dnbhq/secretlint-config.git"},"bugs":{"url":"https://github.com/dnbhq/secretlint-config/issues"},"homepage":"https://github.com/dnbhq/secretlint-config#readme","lint-staged":{"*.{js,json,jsonc,yml,yaml}":"biome check --write --no-errors-on-unmatched","*.{md,mdx}":"markdownlint-cli2 --config ./node_modules/@dnbhq/markdownlint-config/.markdownlint-cli2.jsonc --fix --no-globs","*.{js,json,jsonc,md,mdx,yml,yaml,txt,cjs,mjs,ts,tsx}":"node ./bin/dnb-secretlint.js --no-glob"},"simple-git-hooks":{"pre-commit":"npx lint-staged --allow-empty"},"gitHead":"22cb4caed723aaba08bf63a6f5c4c84b2b4ad370","_id":"@dnbhq/secretlint-config@0.1.1","_nodeVersion":"26.8.1","_npmVersion":"12.0.2","dist":{"integrity":"sha512-vIBWq+nRTs8Sv6Kw4YAsGuQ0kAPVcjVRwZKBAAh0EBzivk1aNJ6u1XRmw+n7gYGmoWee5Ce1a/UMDThPcmhEVQ==","shasum":"56d9a7d3b7c9a3097cf75c061647d90cd50cb72c","tarball":"https://registry.npmjs.org/@dnbhq/secretlint-config/-/secretlint-config-0.1.1.tgz","fileCount":7,"unpackedSize":13626,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dnbhq%2fsecretlint-config@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQD87PhsQEfaLmGQ8Ynph4RUxfnq05YexoWw0hLeEHCHRAIhAN/vlP+e5cBSIwjWoScQCrV9whvnbgTs0r9LElUNZ2kS"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:abe91a55-227b-4297-8c56-65db5beea8e6"}},"directories":{},"maintainers":[{"name":"davidsneighbour","email":"pkollitsch@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/secretlint-config_0.1.1_1787864889824_0.046568311456128386"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-27T21:01:04.467Z","modified":"2026-08-27T21:08:10.350Z","0.1.0":"2026-08-27T21:01:04.806Z","0.1.1":"2026-08-27T21:08:09.987Z"},"bugs":{"url":"https://github.com/dnbhq/secretlint-config/issues"},"author":{"name":"Patrick Kollitsch","email":"davidsneighbourdev+gh@gmail.com","url":"https://davids-neighbour.com"},"license":"MIT","homepage":"https://github.com/dnbhq/secretlint-config#readme","keywords":["secretlint","secrets","linting","config","dnbhq"],"repository":{"type":"git","url":"git+https://github.com/dnbhq/secretlint-config.git"},"description":"Shared Secretlint configuration and CLI for DNBHQ projects.","maintainers":[{"name":"davidsneighbour","email":"pkollitsch@gmail.com"}],"readme":"# @dnbhq/secretlint-config\n\nShared Secretlint configuration and CLI wrapper for DNBHQ projects.\n\nThis package gives projects one maintained baseline for secret scanning. It installs Secretlint, the recommended Secretlint preset, and a small `dnb-secretlint` command that runs Secretlint with the bundled configuration unless a project supplies its own config.\n\n## Installation\n\n```bash\nnpm install --save-dev @dnbhq/secretlint-config\n```\n\nConsumers do not need to install `secretlint` or `@secretlint/secretlint-rule-preset-recommend` separately. They are direct dependencies of this package.\n\n## Requirements\n\n* Node.js 22 or newer.\n* npm.\n* ESM when a local `.secretlintrc.js` imports this package.\n\n## Quick start\n\nMost projects should use the wrapper with no local Secretlint config file:\n\n```json\n{\n  \"scripts\": {\n    \"lint:secrets\": \"dnb-secretlint \\\"**/*\\\"\"\n  }\n}\n```\n\nThen run:\n\n```bash\nnpm run lint:secrets\n```\n\nThe wrapper injects the configuration from this package and passes all other arguments to Secretlint.\n\n## Available entry points\n\n| Entry point | Type | Purpose |\n| --- | --- | --- |\n| `@dnbhq/secretlint-config` | ESM export | Imports the shared Secretlint config object for code-level composition. |\n| `@dnbhq/secretlint-config/config` | ESM export | Alias for the shared config object. |\n| `@dnbhq/secretlint-config/secretlintrc.json` | JSON config | Secretlint rc file used by the CLI wrapper. |\n| `@dnbhq/secretlint-config/secretlintrc` | JSON config | Alias for the Secretlint rc file. |\n| `dnb-secretlint` | CLI command | Runs Secretlint with the shared config by default. |\n\n## Shared configuration\n\nThe current shared config enables Secretlint's recommended preset:\n\n```js\nexport default {\n  rules: [\n    {\n      id: \"@secretlint/secretlint-rule-preset-recommend\"\n    }\n  ]\n};\n```\n\nAdd centrally required rules in `config/index.js` and add their packages to `dependencies` in `package.json`. Keep consumer-only development tools in `devDependencies`.\n\n## CLI wrapper behaviour\n\n`dnb-secretlint` forwards its arguments to Secretlint. When no explicit config argument is present, it prepends this package's bundled config with Secretlint's `--secretlintrc` flag.\n\nThese commands are equivalent in a consuming project:\n\n```bash\ndnb-secretlint \"**/*\"\nsecretlint --secretlintrc ./node_modules/@dnbhq/secretlint-config/config/secretlintrc.json \"**/*\"\n```\n\nThe wrapper leaves project-supplied config arguments untouched. These options take precedence over the bundled config:\n\n| Argument | Behaviour |\n| --- | --- |\n| `--secretlintrc .secretlintrc.js` | Uses the named Secretlint config file. |\n| `--secretlintrc=.secretlintrc.js` | Uses the named Secretlint config file. |\n| `--secretlintrcJSON '{...}'` | Uses inline Secretlint JSON config. |\n| `--secretlintrcJSON={...}` | Uses inline Secretlint JSON config. |\n\nOther Secretlint options are passed through unchanged, for example:\n\n```bash\ndnb-secretlint --format compact \"src/**/*\"\ndnb-secretlint --no-glob README.md package.json\ndnb-secretlint --maskSecrets \"**/*\"\n```\n\n## Local configuration\n\nUse a local config only when a repository needs to differ from the shared defaults.\n\nFor static configuration, use JSON:\n\n```json\n{\n  \"rules\": [\n    {\n      \"id\": \"@secretlint/secretlint-rule-preset-recommend\"\n    }\n  ]\n}\n```\n\nFor code-level composition, import the package from an ESM file and export the final descriptor your own tooling will pass to Secretlint:\n\n```js\nimport baseConfig from \"@dnbhq/secretlint-config\";\n\nexport default {\n  ...baseConfig,\n  rules: [\n    ...baseConfig.rules\n    // Add project-specific rules here.\n  ]\n};\n```\n\nThen either run Secretlint directly with the JSON file:\n\n```json\n{\n  \"scripts\": {\n    \"lint:secrets\": \"secretlint --secretlintrc .secretlintrc.json \\\"**/*\\\"\"\n  }\n}\n```\n\nOr keep the wrapper and point it at the local file:\n\n```json\n{\n  \"scripts\": {\n    \"lint:secrets\": \"dnb-secretlint --secretlintrc .secretlintrc.json \\\"**/*\\\"\"\n  }\n}\n```\n\n## Extending rules\n\nSecretlint config uses a `rules` array. To add a project-specific rule, install the rule package in the consuming project and append it after the base rules:\n\n```js\nimport baseConfig from \"@dnbhq/secretlint-config\";\n\nexport default {\n  ...baseConfig,\n  rules: [\n    ...baseConfig.rules,\n    {\n      id: \"@secretlint/secretlint-rule-example\",\n      options: {\n        example: true\n      }\n    }\n  ]\n};\n```\n\nTo replace the central rule set completely, omit `...baseConfig.rules`. Do that only when the project intentionally opts out of the DNBHQ baseline.\n\n## Ignoring files\n\nSecretlint supports its normal ignore behaviour. Prefer a project-local ignore file when generated files, lock files, fixtures, or vendored content cause noise.\n\nExample:\n\n```bash\ndnb-secretlint --secretlintignore .secretlintignore \"**/*\"\n```\n\nFor lint-staged, pass staged file names directly and disable glob expansion:\n\n```json\n{\n  \"lint-staged\": {\n    \"*.{js,json,md,yml,yaml,txt}\": \"dnb-secretlint --no-glob\"\n  }\n}\n```\n\n## Repository scripts\n\nThis repository uses the same maintenance shape as the other DNBHQ shared config packages:\n\n| Script | Purpose |\n| --- | --- |\n| `npm run lint` | Runs code, Markdown, and secret linting. |\n| `npm run lint:code` | Runs Biome with the shared DNBHQ Biome config. |\n| `npm run lint:code:fix` | Runs Biome in write mode. |\n| `npm run lint:markdown` | Checks Markdown with `@dnbhq/markdownlint-config`. |\n| `npm run lint:markdown:fix` | Fixes Markdown where markdownlint can safely fix it. |\n| `npm run lint:secrets` | Runs this package's CLI wrapper against repository source files. |\n| `npm run lint:staged` | Runs lint-staged for staged files. |\n| `npm test` | Runs the Node.js test suite. |\n| `npm run check` | Runs all linting, tests, and a dry npm pack. |\n| `npm run release:dry` | Runs release-it without publishing, tagging, or pushing. |\n| `npm run release` | Creates the release commit and tag through release-it. |\n\n## Commit checks\n\nThe repository uses `simple-git-hooks` and `lint-staged`.\n\nInstall dependencies to activate the hook:\n\n```bash\nnpm install\n```\n\nThe pre-commit hook runs:\n\n```bash\nnpx lint-staged --allow-empty\n```\n\nStaged JavaScript, JSON, YAML, Markdown, and text-like files are checked with Biome, markdownlint, and this package's Secretlint wrapper as applicable.\n\n## Continuous integration\n\n`.github/workflows/pr.yml` runs `npm run check` on push and pull request events with Node.js 22, 24, and 26.\n\n`.github/workflows/publish.yml` runs when a `v*` tag is pushed. It checks out the tag, installs dependencies with `npm ci`, verifies that the tag matches `package.json` `version`, runs `npm run check`, and publishes the package to npm with provenance.\n\n## Release\n\nReleases use `release-it` and `@dnbhq/release-config`.\n\nDry run:\n\n```bash\nnpm run release:dry\n```\n\nRelease from `main`:\n\n```bash\nnpm run release\n```\n\nThe release command:\n\n* determines the version bump from Conventional Commits,\n* updates `CHANGELOG.md` when release-it creates the release commit,\n* creates a `chore(release): v${version}` commit,\n* creates a `v${version}` tag,\n* pushes the commit and tag, and\n* creates the GitHub release.\n\nThe local release configuration does not publish to npm. npm publishing is handled by the GitHub Actions publish workflow after the release tag is pushed.\n\nThe release config uses `GITHUB_DNBHQ_TOKEN_ADMIN_PRIVATE` for GitHub release access.\n\n## Npm package contents\n\nThe package publishes:\n\n* `bin/` - the `dnb-secretlint` executable.\n* `config/index.js` - the ESM config export.\n* `config/secretlintrc.json` - the Secretlint rc file used by the wrapper.\n* `README.md` - package documentation.\n* `CHANGELOG.md` - generated release history, when present.\n* `LICENSE.md` - MIT licence.\n\nCheck package contents locally with:\n\n```bash\nnpm pack --dry-run\n```\n\n## Development\n\nInstall dependencies:\n\n```bash\nnpm install\n```\n\nRun the full check:\n\n```bash\nnpm run check\n```\n\nRun only the test suite:\n\n```bash\nnpm test\n```\n","readmeFilename":"README.md"}