fix(secrev): commit compliance-drift secret fixture as dotenv.fixture (canary broke on fresh clone)

The compliance-drift canary's planted tracked-secret fixture was BadName_repo/.env,
but the repo root .gitignore lists '.env' — so it was never committed. On a fresh
clone of main the file is absent, the secrets-committed check stops firing, and the
canary FAILS (expected 6, got 5). It only passed where a gitignored, untracked
'.env' happened to exist locally. Verified the failure reproduces in a clean clone
of origin/main (3d97139) and in a fresh worktree.

Fix (in-convention, mirrors the dependency-cve .fixture-suffix trick): ship the
secret as BadName_repo/dotenv.fixture (committable, not gitignored); the --canary
materialization renames dotenv.fixture -> .env in its temp work area. The dotgit/
index already TRACKS .env, so git ls-files still reports it and the drift fires.
Restores the documented 6/6 canary on any fresh checkout. shellcheck stays clean.
This commit is contained in:
Adam Moussa 2026-06-18 15:58:15 -04:00
parent 443297e8e4
commit 31858e02e5
3 changed files with 17 additions and 0 deletions

View file

@ -342,6 +342,13 @@ if [ "$CANARY" -eq 1 ]; then
nm="$(basename "$d")"
cp -R "$d" "$FIXTURE_WORK/$nm"
mv "$FIXTURE_WORK/$nm/dotgit" "$FIXTURE_WORK/$nm/.git"
# The planted-secret env file is shipped as `dotenv.fixture` (NOT `.env`): the repo's
# root .gitignore lists `.env`, so a literal `.env` fixture would never be committed and
# the secrets-committed drift would vanish on a fresh clone. Restore it to `.env` in the
# materialized work area (the dotgit/ index already TRACKS `.env`, so ls-files still
# reports it). Same committable-without-side-effects rationale as the `.fixture` suffix the
# dependency-cve fixtures use for their manifests.
[ -f "$FIXTURE_WORK/$nm/dotenv.fixture" ] && mv "$FIXTURE_WORK/$nm/dotenv.fixture" "$FIXTURE_WORK/$nm/.env"
REPO_NAMES+=( "$nm" ); REPO_DIR["$nm"]="$FIXTURE_WORK/$nm"
done
elif [ -n "$TARGETS_OVERRIDE" ]; then

View file

@ -0,0 +1 @@
API_KEY=AKIAIOSFODNN7EXAMPLE

View file

@ -15,5 +15,14 @@ Fixtures (each a real git checkout so the tracked-`.env` / `ls-files` checks wor
Total = **6** (`EXPECTED_DRIFT_COUNT`). The canary pins `DOCS_ONLY_REPOS=docs-repo` and
`COMPLIANCE_EXEMPT=""` internally so it is deterministic regardless of the operator's env.
**Secret-fixture naming:** `BadName_repo`'s planted tracked-secret env file is committed as
`dotenv.fixture`, NOT `.env`. The repo's root `.gitignore` lists `.env`, so a literal `.env`
fixture would silently never be committed — on a fresh clone the `secrets-committed` drift would
vanish and the count would drop to 5 (this regression was caught by this very canary). The
`--canary` materialization renames `dotenv.fixture` → `.env` in its temp work area; the
`dotgit/` index already TRACKS `.env`, so `git ls-files` still reports it. This mirrors the
`.fixture`-suffix convention the `dependency-cve` fixtures use for their manifests. Keep any new
committed secret fixture under a non-gitignored name and rename it in the canary.
When you add/remove a check or fixture, update both the fixture and `EXPECTED_DRIFT_COUNT`
in the same commit (the canary edit is itself caught on the next run — design §6.4).