Documentation
¶
Overview ¶
Package testutil provides shared helpers for detector tests. It exercises the real matcher -> Scan path so tests can prove that a detector's keywords (or lack thereof) actually let the matcher gate select the detector at runtime.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func RegisteredDetectorFixtures ¶ added in v1.8.0
func RegisteredDetectorFixtures() map[string]DetectorContractFixture
RegisteredDetectorFixtures returns one deliberately non-functional positive fixture for every compile-time detector. The catalog is shared by the registry-wide matcher test and detector-to-verifier contract test so neither layer can prove compatibility with hand-built RawFinding values that a real detector never emits.
func ScanViaMatcher ¶
func ScanViaMatcher(det detector.Detector, data []byte) []detector.RawFinding
ScanViaMatcher runs det through the real Aho-Corasick matcher gate before calling Scan, mirroring the engine pipeline. It returns the findings only if the matcher actually selected det for the given data; if the matcher gates the detector out, an empty slice is returned even when the regex would have matched. This makes keyword/regex misalignment visible in tests.
Types ¶
type DetectorContractFixture ¶ added in v1.8.0
type DetectorContractFixture struct {
Input []byte
ExpectedRaw []byte
ExpectedRawV2 []byte
ExpectedExtraData map[string]string
// NonSecretRawExtraKeys explicitly documents rare fields where Raw is an
// identifier rather than credential material (for example a GCP private key
// ID) and may therefore also appear as non-secret verifier context.
NonSecretRawExtraKeys map[string]bool
RequireExactSpan bool
}
DetectorContractFixture pins the observable contract of one canonical detector example. Expectations are deliberately explicit: a detector cannot widen Raw, drop an exact span, or move credential bytes into ExtraData while retaining a green registry-parity test.