Skip to content

Build realistic test fakes at run time; add narrow secret-scan configs - #35

Merged
imanimanyara merged 2 commits into
mainfrom
chore/secret-hygiene
Oct 8, 2026
Merged

imanimanyara merged 2 commits into
mainfrom
chore/secret-hygiene

Conversation

@imanimanyara

Copy link
Copy Markdown
Member

Two commits.

Test fakes. Two dataset values read to secret scanners as high-entropy secrets:

  • tests/Rules/TrailingNewlineTest.php: the JWT row now comes from a trailingNewlineJwt() helper that assembles header, payload and signature from their claims, the same way IdentifiersRulesTest builds its tokens. The result is byte-identical to the old literal.
  • tests/Rules/Crypto/CryptoRulesTest.php: the mixed-case bech32 row is derived from the lower-case vector with str_replace, which also states what the case is testing.

Narrow configs. .gitguardian.yaml and .gitleaks.toml ignore only tests/Fixtures/**/*, and both are export-ignored.

secret_scan.py check --ref HEAD returns 0. Local gates: pint and rector pass; the two changed test files pass (50 tests). The full suite passed apart from the two activeUrl tests, which need DNS and could not resolve in the local sandbox. phpstan could not start locally (sandbox /tmp restriction), so CI is the phpstan gate here.

Two dataset values read as high-entropy secrets to scanners: a JWT for
the trailing-newline sweep and a mixed-case bech32 address. The JWT is
now assembled from its claims in a helper, byte-identical to the old
literal, and the address is derived from the lower-case vector by
str_replace, which also states what the case is testing.
Ignores only the tracked fixture directory for ggshield and gitleaks, and
keeps both files out of the dist archive.
Copilot AI balanced review requested due to automatic review settings October 8, 2026 11:18

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Benchmark results

Scenario Optimizations Native Laravel Optimized Speedup Δ vs base
Product import — 500 items, simple rules Wildcard, fast-check 96.1ms 1.7ms ~57x +0%
Nested order lines — 1000 orders × 5 line items Wildcard, fast-check (nested) 449.8ms 9.7ms ~46x +2%
Event scheduling — 100 items, field-ref dates Wildcard, partial fast-check 15.2ms 0.7ms ~22x +0%
Article submission — 50 items, custom Rule objects Wildcard only 5.5ms 1.5ms ~4x +0%
Conditional import — 100 items, 47 conditional fields Wildcard, pre-evaluation 119.5ms 27.8ms ~4x +0%
Login form — 3 fields, no wildcards Fast-check (flat) 0.1ms 0.0ms ~9x —

@imanimanyara
imanimanyara merged commit 384610a into main Oct 8, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants