feat(secrev): Plane-1 Phase 4 — plan-groomer + confluence-doc (recommend-only) #20

Merged
amoussa1229 merged 3 commits from feature/agent-team-plane1-phase4 into main 2026-06-18 20:03:38 +00:00
3 changed files with 17 additions and 0 deletions
Showing only changes of commit 31858e02e5 - Show all commits

View file

@ -342,6 +342,13 @@ if [ "$CANARY" -eq 1 ]; then
nm="$(basename "$d")"
cp -R "$d" "$FIXTURE_WORK/$nm"
mv "$FIXTURE_WORK/$nm/dotgit" "$FIXTURE_WORK/$nm/.git"
# The planted-secret env file is shipped as `dotenv.fixture` (NOT `.env`): the repo's
# root .gitignore lists `.env`, so a literal `.env` fixture would never be committed and
# the secrets-committed drift would vanish on a fresh clone. Restore it to `.env` in the
# materialized work area (the dotgit/ index already TRACKS `.env`, so ls-files still
# reports it). Same committable-without-side-effects rationale as the `.fixture` suffix the
# dependency-cve fixtures use for their manifests.
[ -f "$FIXTURE_WORK/$nm/dotenv.fixture" ] && mv "$FIXTURE_WORK/$nm/dotenv.fixture" "$FIXTURE_WORK/$nm/.env"
REPO_NAMES+=( "$nm" ); REPO_DIR["$nm"]="$FIXTURE_WORK/$nm"
done
elif [ -n "$TARGETS_OVERRIDE" ]; then

View file

@ -0,0 +1 @@
API_KEY=AKIAIOSFODNN7EXAMPLE

View file

@ -15,5 +15,14 @@ Fixtures (each a real git checkout so the tracked-`.env` / `ls-files` checks wor
Total = **6** (`EXPECTED_DRIFT_COUNT`). The canary pins `DOCS_ONLY_REPOS=docs-repo` and
`COMPLIANCE_EXEMPT=""` internally so it is deterministic regardless of the operator's env.
**Secret-fixture naming:** `BadName_repo`'s planted tracked-secret env file is committed as
`dotenv.fixture`, NOT `.env`. The repo's root `.gitignore` lists `.env`, so a literal `.env`
fixture would silently never be committed — on a fresh clone the `secrets-committed` drift would
vanish and the count would drop to 5 (this regression was caught by this very canary). The
`--canary` materialization renames `dotenv.fixture` → `.env` in its temp work area; the
`dotgit/` index already TRACKS `.env`, so `git ls-files` still reports it. This mirrors the
`.fixture`-suffix convention the `dependency-cve` fixtures use for their manifests. Keep any new
committed secret fixture under a non-gitignored name and rename it in the canary.
When you add/remove a check or fixture, update both the fixture and `EXPECTED_DRIFT_COUNT`
in the same commit (the canary edit is itself caught on the next run — design §6.4).