mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-21 20:06:37 +00:00
test(crypto): replace the one-file key scan with a repo-wide guard
crates/crypto/src/license_token.rs asserted, via include_str! on its own file, that the license-token signing key is never checked in. The scan saw exactly one file: the key moved anywhere else passed silently, and renaming license_token.rs stopped the guard from compiling instead of reporting. scripts/check_embedded_secrets.sh scans every tracked and not-yet-added text file for the same needle plus the other private-key header forms and eleven provider credential formats, and it does not skip the paths .github/secret_scanning.yml tells push protection to ignore. Non-secret matches are excused by exact literal, never by path glob, and an exemption that stops matching is reported as stale. --self-test asserts every pattern family fires.
This commit is contained in:
@@ -34,6 +34,7 @@ script-tests: ## Run shell script tests
|
||||
./scripts/test_exact_1mib_handoff_abba.sh
|
||||
./scripts/test_pinned_paired_abba_bench.sh
|
||||
./scripts/test_manual_transition_runbooks.sh
|
||||
./scripts/check_embedded_secrets.sh --self-test
|
||||
bash -n ./scripts/validate_object_data_cache_cold_stampede.sh
|
||||
python3 ./scripts/check_object_data_cache_follower_samples.py --self-test
|
||||
./scripts/validate_object_data_cache_cold_stampede.sh --self-test
|
||||
|
||||
Reference in New Issue
Block a user