Skip to content

Mark the published reCAPTCHA test keys in the smoke test - #27

Closed
imanimanyara wants to merge 2 commits into
mainfrom
chore/secret-hygiene
Closed

imanimanyara wants to merge 2 commits into
mainfrom
chore/secret-hygiene

Conversation

@imanimanyara

@imanimanyara imanimanyara commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Summary

  • tests/Feature/Live/ProviderSmokeTest.php: the two lines carrying Google's published reCAPTCHA v2 test key pair end with ggignore gitleaks:allow. The value is the documented always-pass pair and the test depends on it.
  • docs/getting-started.md: the provider-switching example uses example-key instead of a key-shaped 0x4AAA....
  • No ignore config is written: the repository has no tracked fixture or example-env path for it to name. The existing .gitguardian.yaml and its ignored_matches entry are untouched.

A first commit also marked the same pair in src/Credentials/TestKeyCredentialStore.php. That put those lines in the PR diff and the GitGuardian App (incident 36063431, reCAPTCHA Key) flagged them, since it does not read inline markers. That commit is reverted here, so src/ is unchanged. Clearing that incident for good needs a dashboard secret-pattern exclusion for the exact published value; that is the owner's setting.

Secret-scan hygiene, approved by the owner as one PR per repository. secret_scan.py detect found no real secrets.

Verification

  • secret_scan.py check --ref HEAD: exit 0, 2 marked as allowed (was 3 dummy findings).
  • pest: 270 passed; the live group (5 tests, real provider endpoints) passed with network access; BrowserRuntimeTest needs a browser the sandbox does not have. phpstan, laranail-pint --test, rector --dry-run: clean.

The test-key store and the live smoke test carry Google's documented
always-pass reCAPTCHA pair. The value is the feature, so it stays, and
each line now ends with ggignore and gitleaks:allow. The provider
switching example in the docs used a key-shaped placeholder; it now
reads example-key.
Copilot AI balanced review requested due to automatic review settings October 8, 2026 12:27
@gitguardian

gitguardian Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 4 secrets following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secrets in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
36063431 Triggered reCAPTCHA Key 3f61d10 src/Credentials/TestKeyCredentialStore.php View secret
36063431 Triggered reCAPTCHA Key 3f61d10 src/Credentials/TestKeyCredentialStore.php View secret
36063431 Triggered reCAPTCHA Key c2ac0c0 src/Credentials/TestKeyCredentialStore.php View secret
36063431 Triggered reCAPTCHA Key c2ac0c0 src/Credentials/TestKeyCredentialStore.php View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Editing the lines that hold Google's published reCAPTCHA pair puts them in
the pull request diff, and the GitGuardian GitHub App, which does not read
inline markers, reports them there. The store keeps its existing
ignored_matches entry in .gitguardian.yaml; the markers stay on the smoke
test and the docs example.
@imanimanyara imanimanyara changed the title Mark the published reCAPTCHA test keys for secret scanners Mark the published reCAPTCHA test keys in the smoke test Oct 8, 2026

Copy link
Copy Markdown
Member Author

Superseded by #28 (docs only; the reCAPTCHA test-key lines are left alone so GitGuardian has nothing to flag). Branch kept.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants