Skip to content

fix(secrets): scan high-confidence secrets in test/fixture paths - #583

Merged
ajianaz merged 1 commit into
developfrom
fix/secrets-scanner-test-paths
Oct 8, 2026
Merged

ajianaz merged 1 commit into
developfrom
fix/secrets-scanner-test-paths

Conversation

@ajianaz

@ajianaz ajianaz commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Closes #579

What

secrets_scanner skipped every test/spec/fixture/mock/example path before looking at any line, so real credentials committed there were never reported. Test/fixture paths now run only a high-confidence list; the noisy generic rules stay suppressed there.

  • New src/engine/secret_patterns.rs holds the single shared list (AWS access key, private-key header incl. PGP, GitHub tokens, Slack tokens, Stripe sk_live_) plus placeholder handling. security_scanner (from fix(llm): harden response parsing, prompt injection and stream limits #573) and secrets_scanner both use it, so they agree.
  • Placeholders ignored: values containing EXAMPLE, and long xxxx filler (e.g. ghp_xxxx...). The xxxx rule is new and also applies to the security scanner.
  • Source paths are unchanged.

Why

Real credentials are often committed in test setup, fixtures and examples; skipping those paths entirely hid them. #573 already covered the static security scanner, so the two scanners disagreed for the same file (follow-up from #573).

User-visible

cora review/hooks now report real-looking AWS/GitHub/Slack/Stripe-live keys and private-key headers in tests/, examples/, fixtures/, test_*/spec_* files (Critical, value masked). No CHANGELOG edit per contributing flow.

Testing

Reported in tests/, examples/, spec/, fixtures/, test_*.py, *_test.go; placeholders not reported; generic password, JWT, sk_test_ still suppressed in test paths; same lines in src/ report as before; both scanners agree on every shared pattern. Fixture keys are built at runtime. fmt, clippy -D warnings, full tests pass.

🤖 Generated with Claude Code

secrets_scanner skipped test/spec/fixture/mock/example paths entirely, so
real leaked credentials committed there were never reported. Extract the
high-confidence list from security_scanner into engine::secret_patterns
and run it in those paths from both scanners; generic rules stay
suppressed there.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
@ajianaz
ajianaz merged commit f620602 into develop Oct 8, 2026
16 of 17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(secrets): secrets_scanner skips test/spec/fixture/example paths entirely

1 participant