Repository navigation
fix(secrets): scan high-confidence secrets in test/fixture paths - #583
Merged
Merged
Conversation
secrets_scanner skipped test/spec/fixture/mock/example paths entirely, so real leaked credentials committed there were never reported. Extract the high-confidence list from security_scanner into engine::secret_patterns and run it in those paths from both scanners; generic rules stay suppressed there. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #579
What
secrets_scannerskipped every test/spec/fixture/mock/example path before looking at any line, so real credentials committed there were never reported. Test/fixture paths now run only a high-confidence list; the noisy generic rules stay suppressed there.src/engine/secret_patterns.rsholds the single shared list (AWS access key, private-key header incl. PGP, GitHub tokens, Slack tokens, Stripesk_live_) plus placeholder handling.security_scanner(from fix(llm): harden response parsing, prompt injection and stream limits #573) andsecrets_scannerboth use it, so they agree.EXAMPLE, and longxxxxfiller (e.g.ghp_xxxx...). Thexxxxrule is new and also applies to the security scanner.Why
Real credentials are often committed in test setup, fixtures and examples; skipping those paths entirely hid them. #573 already covered the static security scanner, so the two scanners disagreed for the same file (follow-up from #573).
User-visible
cora review/hooks now report real-looking AWS/GitHub/Slack/Stripe-live keys and private-key headers intests/,examples/,fixtures/,test_*/spec_*files (Critical, value masked). No CHANGELOG edit per contributing flow.Testing
Reported in tests/, examples/, spec/, fixtures/,
test_*.py,*_test.go; placeholders not reported; genericpassword, JWT,sk_test_still suppressed in test paths; same lines insrc/report as before; both scanners agree on every shared pattern. Fixture keys are built at runtime. fmt, clippy-D warnings, full tests pass.🤖 Generated with Claude Code