Skip to content

Commit 29f5b33

Browse files
ci: mark deliberate secret-shaped test fixtures for rust-secrets (#101)
standards' `rust-secrets` job becomes **blocking outside `./src`** on **2026-08-21** (warn-first window from standards#518). The lines tagged here are **genuine matches on genuine secret-shaped literals** — they are test data, not credentials. So they take an explicit, auditable per-line pragma rather than a pattern loophole that would weaken the gate for every repo in the estate. ```rust // scanner-allow: rust-secrets ``` ## Why a pragma and not a pattern change standards#523 already tightens the patterns to require an assignment **directly to a string literal** of length ≥ 8, which removes the real false positives estate-wide (lookups, path joins, prose). What remains here genuinely *is* an assignment of a secret-shaped literal — it just happens to be fixture data. Loosening the pattern to hide it would blind the gate everywhere. ## Fixture integrity Where the pragma sits **outside** the `r#"…"#` raw string (after the closing quote/comma) it is an ordinary Rust comment and the fixture content is **byte-identical** — the tests exercise exactly the same data. Where it sits **inside** a multi-line fixture, it is a JS-style comment within fake content and does not change what the test asserts. ## Verified `rust-secrets`, extracted from standards' shipping YAML, exits **0** on this tree with `RUST_TODAY=2026-09-01` — i.e. after the cutoff, when the check is blocking. ## Scope **Only Rust sources.** The secret-scanner re-pin is deliberately not bundled: this repo is one of the 22 the estate sweep flagged, where gitleaks findings survive the shared baseline, and moving it onto the real gate needs its own triage. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
1 parent 08c06ec commit 29f5b33

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

fuzz/fuzz_targets/fuzz_hmac.rs

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ use hmac::{Hmac, Mac};
1414
use sha2::Sha256;
1515

1616
// Fixed secret — we're testing the parsing/comparison path, not the secret itself
17-
const SECRET: &[u8] = b"fuzz-test-secret-key-not-real";
17+
const SECRET: &[u8] = b"fuzz-test-secret-key-not-real"; // scanner-allow: rust-secrets
1818

1919
fuzz_target!(|data: &[u8]| {
2020
// Split data: first 32 bytes treated as a "claimed signature", rest as body

0 commit comments

Comments
 (0)