mirror of
https://github.com/kellymichels/zscripts-token-savers
synced 2026-10-07 07:18:18 +00:00
The rules lived inside Sanitization.Tests.ps1, so the publisher in the private toolkit kept its own second list -- and the two guarded different things. The publisher's was about SECRETS: keys, private-key blocks, ssh targets. These are about IDENTITY: internal project names, product domains, private-only script names, operator paths. So the publisher reported "clean" on files this suite rejects, and would have published a tree that fails the public repo's own tests (evo.scripts#106). Proven at the time by copying the private ZHelpers.ps1 in: two failures naming EvoCivilCode, EvoPlatform and three private-only script names, against a scan that called the same file clean. tests/sanitization-patterns.psd1 is now the one source. The suite reads it and refuses to run if it is missing or empty, rather than passing vacuously against no rules -- an empty denylist that reports success is the failure this whole fix is about. No rule changed. Only where they live. .psd1 is not in the scanned extension list, which is deliberate and matches why Sanitization.Tests.ps1 excludes itself: a file that necessarily contains every pattern it looks for cannot also be scanned for them. Pester: 240 passed, 0 failed. CHECKSUMS regenerated; changelog and its plain-text twin updated. |
||
|---|---|---|
| .. | ||
| fixtures | ||
| ArgumentParsing.Tests.ps1 | ||
| Checksums.Tests.ps1 | ||
| Invoke-Coverage.ps1 | ||
| NewProjectArchive.Tests.ps1 | ||
| sanitization-patterns.psd1 | ||
| Sanitization.Tests.ps1 | ||
| VerifyPlan.Tests.ps1 | ||
| ZHelpers.Tests.ps1 | ||