The compliance-drift canary's planted tracked-secret fixture was BadName_repo/.env,
but the repo root .gitignore lists '.env' — so it was never committed. On a fresh
clone of main the file is absent, the secrets-committed check stops firing, and the
canary FAILS (expected 6, got 5). It only passed where a gitignored, untracked
'.env' happened to exist locally. Verified the failure reproduces in a clean clone
of origin/main (
|
||
|---|---|---|
| .. | ||
| fixtures | ||
| compliance-drift.sh | ||
| confluence-doc.sh | ||
| dependency-cve.sh | ||
| plan-groomer.sh | ||