Skip to content

fix(secrets): secrets_scanner skips test/spec/fixture/example paths entirely #579

Description

@ajianaz

Problem. src/engine/secrets_scanner.rs skips every file matching TEST_FIXTURE_RE (tests?, specs?, fixtures?, mocks?, examples? as a path segment or test_*/spec_* prefix) before looking at any line (line ~125). Real leaked credentials are often committed in exactly those places (copy-pasted real keys in test setup, example configs, docs samples).

Context. #573 added a high-confidence secret check to the static security scanner for test/doc paths (AWS access keys, private-key headers, GitHub/Slack/Stripe live tokens; values containing EXAMPLE ignored). The dedicated secrets scanner still has no such fallback, so the two disagree for the same file.

Direction. In test/fixture paths, keep skipping the noisy generic rules but still run the high-confidence, low-false-positive patterns (reuse the same list as #573 rather than duplicating it). Add tests: AWS key in tests/ is reported, placeholder/EXAMPLE values are not, noisy generic rules stay suppressed.

Follow-up noted in #573.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions