RELEASE V1.0.0
Xipper
XIPPERCODEBASE PACKAGER
TECHNICAL SPECIFICATIONS

HOW THE ENGINE WORKS

The deterministic 6-layer exclusion pipeline, active secret scanner heuristics, and zero-egress architectural security guarantees.

1. DETERMINISTIC 6-LAYER EXCLUSION

Every single file or directory encountered during an async walk is evaluated through a strict, deterministic hierarchy before inclusion:

LAYER 1: UNIVERSAL DEFAULTSALWAYS APPLIED

Purges system and OS noise: .git, .DS_Store, Thumbs.db, *.log, .cache, .tmp, tmp/.

LAYER 2: PER-STACK DEFAULTSAUTO-DETECTED

Detects marker files (package.json, requirements.txt, Cargo.toml, go.mod) and eliminates bulky dependencies and build folders (node_modules, dist, venv, target, bin/obj).

LAYER 3: ROOT .GITIGNOREOPTIONAL INPUT

Parses the project root .gitignore file using standard gitignore semantics. Layers on top of stack defaults without discarding them.

LAYER 4: NESTED MONOREPO .GITIGNORESSCOPED SUBTREES

Discovers nested .gitignore files inside packages or services and scopes rules specifically to their relative subtrees.

LAYER 5: SENSITIVE FILENAME LISTSHARD-FLAGGED

Pre-excludes and flags secret-named files: .env*, *.pem, *.key, id_rsa, credentials.json, service-account*.json.

LAYER 6: ACTIVE USER PROFILECUSTOM OVERRIDE

Applies user-selected saved profiles to force-include or force-exclude specific patterns.

2. TWO-LAYER SECRET DETECTION

The content secret scanner acts as an active second layer on top of filename exclusion. It reads candidate text files line-by-line (skipping binaries via isbinaryfile and files over 2 MB) to catch accidental credential leaks:

HIGH-CONFIDENCE RULES

  • • AWS Access Key ID (AKIA...) & secret keys
  • • GCP Service Account JSON structure
  • • Azure Storage connection strings
  • • GitHub Personal Access Tokens (ghp_...)
  • • Stripe & OpenAI live API keys
  • • Private key headers (BEGIN RSA PRIVATE KEY)
  • • Generic variable assignments (api_key = "...")

HEURISTICS & ENTROPY

  • • JSON Web Tokens (3-segment base64url shape)
  • • Shannon entropy > 4.65 bits/char
  • • Placeholder filter (rejects your_key_here)
  • • Zero raw credential leak in UI or logs
HONEST LIMITS & RESPONSIBLE DISCLOSURE:

The secret scanner is an active safety net designed to catch common accidents. It is not a substitute for proper secrets management and cannot guarantee detection of custom-encrypted or highly obfuscated strings. Always inspect the tree preview before sharing sensitive repos.

3. AIR-GAPPED PRIVACY GUARANTEE

Xipper never transmits file names, paths, or code off your machine. The Electron renderer operates in a sandboxed process with nodeIntegration: false and contextIsolation: true. Local diagnostic logs in app.log never contain file contents and are capped at 5 MB with rotation.