#!/usr/bin/env bash # test_secret_scan.sh — self-test for the commit-time secret guard. # # Run: bash tests/test_secret_scan.sh # Exit: 0 all cases passed, 1 a case failed. # # WHY THIS FILE EXISTS: a scanner that is never observed to fail is not a guard. # Every fixture below is fabricated and pattern-shaped; the test writes it to a # temp tree (a path no allowlist entry covers) and asserts the guard FAILS. The # same fixtures are deliberately listed in scripts/secret-allowlist.tsv, so the # repo-wide tree scan stays quiet while a planted copy still bites — that is the # difference between an explicit, reasoned exception and a guard trained to # ignore a word. # # Only bash + coreutils + grep. No python/node: the Gitea runner executes job # steps inside the runner container, which has neither. set -uo pipefail HERE=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd) ROOT=$(cd -- "$HERE/.." && pwd) SCAN="$ROOT/scripts/secret-scan.sh" PASS=0 FAIL=0 LAST_OUT="" ok() { PASS=$((PASS + 1)); echo " ✅ $1"; } bad() { FAIL=$((FAIL + 1)); echo " ❌ $1"; } expect_exit() { # expect_exit