Security and Fixtures
This repository includes validator fixtures that intentionally resemble credentials so the secret-scanning and evidence-redaction gates can be tested.
The canonical fixture policy is:
Fixture Rule
Fake secret fixtures must draw from the documented allowlist and include the
required SECRETS FIXTURE POLICY header. Out-of-allowlist credential-shaped
content in fixtures is treated as a failure, not as harmless test data.
Scanner and Redactor
Relevant implementation files:
Relevant tests and fixtures:
Public Release Linkage
The root SECURITY.md links back to this page and the
canonical fixture policy. Keep both surfaces aligned when fixture policy,
GitGuardian configuration, or redaction behavior changes.