Skip to content

Use readable placeholder tokens in the GitHub provider test - #45

Merged
imanimanyara merged 1 commit into
mainfrom
chore/secret-hygiene
Oct 8, 2026
Merged

imanimanyara merged 1 commit into
mainfrom
chore/secret-hygiene

Conversation

@imanimanyara

Copy link
Copy Markdown
Member

Summary

src/internal/core/providers/vcs_test.go set GH_TOKEN and GH_ENTERPRISE_TOKEN to dotcom-token and ghes-token, which scanners read as literal credentials. They are now test-secret-not-real-dotcom and test-secret-not-real-ghes; the test still tells the two apart.

No config change: check --write found nothing to add, and .gitleaksignore is unchanged.

Verified locally: secret_scan.py check --ref HEAD exits 0. Gates: make fmt-check vet build-all, and the provider tests that cover this file pass. Tests that bind a local port cannot run in this sandbox.

dotcom-token and ghes-token on GH_TOKEN and GH_ENTERPRISE_TOKEN read as
literal credentials to secret scanners. Use test-secret-not-real-dotcom
and test-secret-not-real-ghes; the test still tells the two apart.
Copilot AI balanced review requested due to automatic review settings October 8, 2026 11:23

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@imanimanyara
imanimanyara merged commit 97ef491 into main Oct 8, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants