惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
aimingoo的专栏
aimingoo的专栏
S
SegmentFault 最新的问题
博客园_首页
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
博客园 - 【当耐特】
月光博客
月光博客
C
Check Point Blog
T
The Blog of Author Tim Ferriss
罗磊的独立博客
博客园 - Franky
MongoDB | Blog
MongoDB | Blog
H
Help Net Security
Microsoft Security Blog
Microsoft Security Blog
B
Blog
阮一峰的网络日志
阮一峰的网络日志
腾讯CDC
美团技术团队
N
Netflix TechBlog - Medium
Stack Overflow Blog
Stack Overflow Blog
Y
Y Combinator Blog
L
LangChain Blog
The Cloudflare Blog

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
test: clarify secrets audit findings · openclaw/openclaw@...
steipete · 2026-05-08 · via Recent Commits to openclaw:main

@@ -220,8 +220,12 @@ describe("secrets audit", () => {

220220

expect(report.status).toBe("findings");

221221

expect(report.summary.plaintextCount).toBeGreaterThan(0);

222222

expect(report.summary.shadowedRefCount).toBeGreaterThan(0);

223-

expect(hasFinding(report, (entry) => entry.code === "REF_SHADOWED")).toBe(true);

224-

expect(hasFinding(report, (entry) => entry.code === "PLAINTEXT_FOUND")).toBe(true);

223+

expect(report.findings).toEqual(

224+

expect.arrayContaining([

225+

expect.objectContaining({ code: "REF_SHADOWED" }),

226+

expect.objectContaining({ code: "PLAINTEXT_FOUND" }),

227+

]),

228+

);

225229

});

226230227231

it("does not mutate legacy auth.json during audit", async () => {

@@ -234,7 +238,9 @@ describe("secrets audit", () => {

234238

});

235239236240

const report = await runSecretsAudit({ env: fixture.env });

237-

expect(hasFinding(report, (entry) => entry.code === "LEGACY_RESIDUE")).toBe(true);

241+

expect(report.findings).toEqual(

242+

expect.arrayContaining([expect.objectContaining({ code: "LEGACY_RESIDUE" })]),

243+

);

238244

const authJsonStat = await fs.stat(fixture.authJsonPath);

239245

expect(authJsonStat.isFile()).toBe(true);

240246

await expect(fs.stat(fixture.authStorePath)).rejects.toMatchObject({ code: "ENOENT" });

@@ -245,9 +251,13 @@ describe("secrets audit", () => {

245251

await fs.writeFile(fixture.authJsonPath, "{invalid-json", "utf8");

246252247253

const report = await runSecretsAudit({ env: fixture.env });

248-

expect(hasFinding(report, (entry) => entry.file === fixture.authStorePath)).toBe(true);

249-

expect(hasFinding(report, (entry) => entry.file === fixture.authJsonPath)).toBe(true);

250-

expect(hasFinding(report, (entry) => entry.code === "REF_UNRESOLVED")).toBe(true);

254+

expect(report.findings).toEqual(

255+

expect.arrayContaining([

256+

expect.objectContaining({ file: fixture.authStorePath }),

257+

expect.objectContaining({ file: fixture.authJsonPath }),

258+

expect.objectContaining({ code: "REF_UNRESOLVED" }),

259+

]),

260+

);

251261

});

252262253263

it("skips exec ref resolution during audit unless explicitly allowed", async () => {