Skip to content

Stdout/stderr canary sweep test for credential secret leakage #135

Description

@simongdavies

Follow-up from #89 (Scoped credentials for outgoing HTTP).

Existing tests cover some leakage paths: resolver_failure_surfaces_as_error asserts the failure diagnostic does not leak, and isolated_registries_across_sandboxes proves cross-sandbox isolation.

However, there is no positive test that runs a guest with a known sentinel token value and scans stdout / stderr / every error payload to assert the sentinel string is absent from every guest-visible output. Add such a canary sweep test.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions