Trust and secrets
Trust
Request files are shell scripts, so a cloned collection never runs until you trust it:
sankh trust my-apiTrust is stored in ~/.config/sankh/trust.toml (or $SANKH_CONFIG_DIR). In a
git repository the HEAD commit is recorded, and trust lapses when HEAD changes,
so pulled changes are reviewed before they run.
Running an untrusted collection exits with code 3. In CI, where the checkout
is the code under review, pass --trust or set SANKH_TRUST=1.
Secrets
- Values of variables whose names contain
TOKEN,SECRET,KEY,PASSWORD,AUTHorCOOKIEare replaced with***in all output, reports and UI responses, including captured values. - Keep secrets in
.env.local(gitignored) or CI secrets, never inenvironments/*.env.
Known limitation
The shell expands variables into curl's arguments, so a secret can appear in
the process list (ps) while a request runs. Use curl's -H @file or
--config in a request file if that matters.
Telemetry
None. Sankh makes no network requests other than the ones in your files.