Skip to content

Rewrite placeholder credentials in tests and docs - #24

Merged
imanimanyara merged 2 commits into
mainfrom
chore/secret-hygiene
Oct 8, 2026
Merged

imanimanyara merged 2 commits into
mainfrom
chore/secret-hygiene

Conversation

@imanimanyara

Copy link
Copy Markdown
Member

Summary

Rewrites the placeholder credentials secret scanners read as real. Two commits:

  • Tests: the Django and Symfony DSN tests build the expected URL from DbConfig().default_password instead of a root:shimkit-dev@ literal; the env reveal and redaction tests use test-secret-not-real; the Route53 credentials fixture uses example-key (nothing validates its shape). Same assertions.
  • Docs: the AWS credentials file example uses <your-access-key-id> / <your-secret-access-key>, and the DSN examples in CHANGELOG and release notes use <password>, with one line naming db.default_password (shimkit-dev) beside each so no detail is lost.

No product behaviour changes: the scaffolders still write shimkit-dev. No config change: no fixture or example-env paths.

Verified locally: secret_scan.py check --ref HEAD exits 0. Gates: ruff check, mypy, pytest with coverage (84.85%, floor 84). 6 tests fail on this macOS host, and the same 6 fail on main.

The framework DSN tests now build the expected URL from
DbConfig().default_password instead of carrying root:<pw>@ literals,
the env reveal and redaction tests use test-secret-not-real, and the
Route53 credentials fixture uses example-key. Assertions are unchanged.
Show the AWS credentials file with <your-access-key-id> and
<your-secret-access-key>, and the local DSNs with <password>, naming
db.default_password (shimkit-dev) once beside each example so no
detail is lost.
Copilot AI balanced review requested due to automatic review settings October 8, 2026 11:23

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@imanimanyara
imanimanyara merged commit 4a4cbea into main Oct 8, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants