Repository navigation
Build realistic test fakes at run time; add narrow secret-scan configs - #35
Merged
Merged
Conversation
Two dataset values read as high-entropy secrets to scanners: a JWT for the trailing-newline sweep and a mixed-case bech32 address. The JWT is now assembled from its claims in a helper, byte-identical to the old literal, and the address is derived from the lower-case vector by str_replace, which also states what the case is testing.
Ignores only the tracked fixture directory for ggshield and gitleaks, and keeps both files out of the dist archive.
Benchmark results
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two commits.
Test fakes. Two dataset values read to secret scanners as high-entropy secrets:
tests/Rules/TrailingNewlineTest.php: the JWT row now comes from atrailingNewlineJwt()helper that assembles header, payload and signature from their claims, the same wayIdentifiersRulesTestbuilds its tokens. The result is byte-identical to the old literal.tests/Rules/Crypto/CryptoRulesTest.php: the mixed-case bech32 row is derived from the lower-case vector withstr_replace, which also states what the case is testing.Narrow configs.
.gitguardian.yamland.gitleaks.tomlignore onlytests/Fixtures/**/*, and both are export-ignored.secret_scan.py check --ref HEADreturns 0. Local gates: pint and rector pass; the two changed test files pass (50 tests). The full suite passed apart from the twoactiveUrltests, which need DNS and could not resolve in the local sandbox. phpstan could not start locally (sandbox/tmprestriction), so CI is the phpstan gate here.