Skip to content

Rewrite fake credentials and add narrow secret-scan configs - #32

Merged
imanimanyara merged 2 commits into
mainfrom
chore/secret-hygiene
Oct 8, 2026
Merged

imanimanyara merged 2 commits into
mainfrom
chore/secret-hygiene

Conversation

@imanimanyara

Copy link
Copy Markdown
Member

Summary

  • tests/Feature/Webhooks/WebhookDeliveryTest.php: the signing secret whsec_test_0123… matched gitleaks' generic-api-key rule. It is now test-secret-not-real; the test signs and verifies with whatever the vault holds, so every assertion stands.
  • Adds the narrow .gitguardian.yaml (secret.ignored_paths) and .gitleaks.toml written by agent-kit's secret_scan.py check --write. They name only the tracked test fixture directory; nothing under src/, no whole test tree and no detector is excluded. The paths are worth mirroring into the GitGuardian dashboard exclusion rules, since the GitHub App does not read the repository file.
  • Export-ignores both files so the dist archive is unchanged.

Secret-scan hygiene, approved by the owner as one PR per repository. secret_scan.py detect found no real secrets.

Verification

  • secret_scan.py check --ref HEAD: exit 0. gitleaks with the new config: no leaks in tracked files.
  • pest (390 passed), phpstan, laranail-pint --test, rector --dry-run: clean locally.

whsec_test_0123456789abcdef matches gitleaks' generic API key rule. The
test signs and verifies with whatever the vault holds, so
test-secret-not-real keeps every assertion.
Ignore only the named test fixture directory in ggshield and gitleaks,
written by agent-kit's secret_scan.py, and keep both files out of the
dist archive. Nothing under src/, no whole test tree and no detector is
excluded.
Copilot AI balanced review requested due to automatic review settings October 8, 2026 12:27

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@imanimanyara
imanimanyara merged commit 885a237 into main Oct 8, 2026
13 of 14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants