This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review/checkers
Adam Moussa 31858e02e5 fix(secrev): commit compliance-drift secret fixture as dotenv.fixture (canary broke on fresh clone)
The compliance-drift canary's planted tracked-secret fixture was BadName_repo/.env,
but the repo root .gitignore lists '.env' — so it was never committed. On a fresh
clone of main the file is absent, the secrets-committed check stops firing, and the
canary FAILS (expected 6, got 5). It only passed where a gitignored, untracked
'.env' happened to exist locally. Verified the failure reproduces in a clean clone
of origin/main (3d97139) and in a fresh worktree.

Fix (in-convention, mirrors the dependency-cve .fixture-suffix trick): ship the
secret as BadName_repo/dotenv.fixture (committable, not gitignored); the --canary
materialization renames dotenv.fixture -> .env in its temp work area. The dotgit/
index already TRACKS .env, so git ls-files still reports it and the drift fires.
Restores the documented 6/6 canary on any fresh checkout. shellcheck stays clean.
2026-06-18 15:58:15 -04:00
..
fixtures fix(secrev): commit compliance-drift secret fixture as dotenv.fixture (canary broke on fresh clone) 2026-06-18 15:58:15 -04:00
compliance-drift.sh fix(secrev): commit compliance-drift secret fixture as dotenv.fixture (canary broke on fresh clone) 2026-06-18 15:58:15 -04:00
confluence-doc.sh feat(secrev): confluence-doc Plane-1 Phase 4 doc-gap detector (recommend-only) 2026-06-18 15:58:04 -04:00
dependency-cve.sh feat(secrev): Plane-1 Phase 2 — coordinator + dependency-cve checker (#16) 2026-06-18 15:08:58 -04:00
plan-groomer.sh feat(secrev): plan-groomer Plane-1 Phase 4 planner (report-only) 2026-06-18 15:51:45 -04:00