diff --git a/.gitleaks.toml b/.gitleaks.toml
index 3587bd4..8a35146 100644
--- a/.gitleaks.toml
+++ b/.gitleaks.toml
@@ -1,6 +1,15 @@
# Homelab bootstrap — gitleaks allowlist (tests, examples, placeholders)
+#
+# IMPORTANT: `useDefault = true` is required — without it gitleaks loads ONLY
+# this file (title + allowlist) with ZERO detection rules, so it would never
+# flag a real secret. Fixed 2026-07 (security-hardening track); if you're
+# re-pushing this template to a repo that already had the old version, that
+# repo's secret scanning was a no-op until this lands.
title = "homelab gitea bootstrap"
+[extend]
+useDefault = true
+
[allowlist]
description = "Test fixtures and example configs are not production secrets"
paths = [
diff --git a/index.html b/index.html
index 97904a9..e278742 100644
--- a/index.html
+++ b/index.html
@@ -16,14 +16,16 @@
-
-
+
+
+
+
-
+