Problem. src/engine/secrets_scanner.rs skips every file matching TEST_FIXTURE_RE (tests?, specs?, fixtures?, mocks?, examples? as a path segment or test_*/spec_* prefix) before looking at any line (line ~125). Real leaked credentials are often committed in exactly those places (copy-pasted real keys in test setup, example configs, docs samples).
Context. #573 added a high-confidence secret check to the static security scanner for test/doc paths (AWS access keys, private-key headers, GitHub/Slack/Stripe live tokens; values containing EXAMPLE ignored). The dedicated secrets scanner still has no such fallback, so the two disagree for the same file.
Direction. In test/fixture paths, keep skipping the noisy generic rules but still run the high-confidence, low-false-positive patterns (reuse the same list as #573 rather than duplicating it). Add tests: AWS key in tests/ is reported, placeholder/EXAMPLE values are not, noisy generic rules stay suppressed.
Follow-up noted in #573.
Problem.
src/engine/secrets_scanner.rsskips every file matchingTEST_FIXTURE_RE(tests?,specs?,fixtures?,mocks?,examples?as a path segment ortest_*/spec_*prefix) before looking at any line (line ~125). Real leaked credentials are often committed in exactly those places (copy-pasted real keys in test setup, example configs, docs samples).Context. #573 added a high-confidence secret check to the static security scanner for test/doc paths (AWS access keys, private-key headers, GitHub/Slack/Stripe live tokens; values containing
EXAMPLEignored). The dedicated secrets scanner still has no such fallback, so the two disagree for the same file.Direction. In test/fixture paths, keep skipping the noisy generic rules but still run the high-confidence, low-false-positive patterns (reuse the same list as #573 rather than duplicating it). Add tests: AWS key in
tests/is reported, placeholder/EXAMPLEvalues are not, noisy generic rules stay suppressed.Follow-up noted in #573.