Repository navigation
Rewrite fake credentials and add narrow secret-scan configs - #32
Merged
Merged
Conversation
whsec_test_0123456789abcdef matches gitleaks' generic API key rule. The test signs and verifies with whatever the vault holds, so test-secret-not-real keeps every assertion.
Ignore only the named test fixture directory in ggshield and gitleaks, written by agent-kit's secret_scan.py, and keep both files out of the dist archive. Nothing under src/, no whole test tree and no detector is excluded.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
tests/Feature/Webhooks/WebhookDeliveryTest.php: the signing secretwhsec_test_0123…matched gitleaks'generic-api-keyrule. It is nowtest-secret-not-real; the test signs and verifies with whatever the vault holds, so every assertion stands..gitguardian.yaml(secret.ignored_paths) and.gitleaks.tomlwritten by agent-kit'ssecret_scan.py check --write. They name only the tracked test fixture directory; nothing undersrc/, no whole test tree and no detector is excluded. The paths are worth mirroring into the GitGuardian dashboard exclusion rules, since the GitHub App does not read the repository file.Secret-scan hygiene, approved by the owner as one PR per repository.
secret_scan.py detectfound no real secrets.Verification
secret_scan.py check --ref HEAD: exit 0. gitleaks with the new config: no leaks in tracked files.