Where Is the Gitleaks Config File?
Gitleaks reads .gitleaks.toml in the repo root for custom rules, falling back to builtin defaults.
Last updated
Gitleaks configures from a TOML file at the repository root. The .gitleaks.toml file extends or replaces builtin rules with custom patterns and allowlists. No file means the default rule set scans everything.
CI setups often pin a shared config by URL or volume mount. Baseline files for known findings sit beside the config when teams adopt gradually. Keep the file in git so every checkout scans identically.
Where Gitleaks stores this, by platform
[Repo]/.gitleaks.toml
Custom rules plus allowlists for the repo. Flags override per run for one off scans. Baseline files beside it track accepted findings.
[Repo]/.gitleaks.toml
Same root file on Mac. Pre commit hooks read it through the repo path. Keep rule changes reviewed like code.
[Repo]\.gitleaks.toml
Same file on Windows. Path handling inside follows the repo root. Exact filename variants like .yaml also resolve by version.
Frequently asked questions
How do I ignore a false positive?
Add an allowlist entry for the path or pattern in .gitleaks.toml. Prefer narrow rules over broad ignores. Re scan to confirm the finding clears.
Can Gitleaks use a shared org config?
Yes by pointing the config flag at a central file or URL in CI. Repos keep small extensions locally. Pin the shared file to a version.
Notice an outdated path? Let us know.