Documentation
¶
Overview ¶
Package testsecret builds synthetic, secret-shaped strings at RUNTIME for tests that must exercise the secret scanner and its adapters. No literal secret is ever committed to source, so the full-history secret scan (gitleaks git, fetch-depth 0 in CI) has nothing to find — see the principle secret-shaped-fixtures-at-runtime. A committed literal, even a fake one, trips the scan on the commit that added it and cannot be removed without a history rewrite, so the fixture is generated instead.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func Synthetic ¶
Synthetic returns a deterministic length-n high-entropy alphanumeric string shaped like a generic API key, built at runtime from seed. It is stable for a given (seed, n) so tests are reproducible, and it never appears verbatim in source. n is clamped to at least 1.
func SyntheticHex ¶
SyntheticHex returns a deterministic length-n lower-case hex string built at runtime from seed — the other spelling an opaque identifier takes (a hex session id, and the runs a UUID is assembled out of). Same contract as Synthetic: stable for a given (seed, n), never verbatim in source, n clamped to at least 1.
Types ¶
This section is empty.