chore: keep tests, examples and benches out of the published crates - #1
Merged
Merged
Conversation
`core/tests/fixtures/` holds RSA and EC private keys that the unit tests and the DPoP example load through `include_str!`. They are test material — nothing in the SDK verifies against them — but `cargo package --list` showed all four shipping inside the `authplane-sdk` tarball, and a crates.io version is immutable: whatever 0.1.0 carries, it carries for good. Key-shaped files in a published tarball are permanent noise for every downstream secret scanner and SBOM, so the cheapest moment to keep them out is before the first publish. `examples/` is excluded alongside `tests/` rather than kept: the DPoP example reads `tests/fixtures/test-private.pem`, so shipping it without the fixture would leave it unbuildable from the tarball. Both stay in the repository, which is where anyone reading them is already looking. Packaging only — no source, no API and no test behaviour changes. The suites still run from a checkout, and `cargo package -p authplane-sdk` verifies clean with no `.pem` in the result. `authplane-mcp` and `authplane-fastmcp` cannot be packaged until `authplane-sdk` is on the index, which is the publish order RELEASE_SETUP.md already prescribes.
muralx
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Packaging metadata only — no source, no API, no test behaviour changes. Three
Cargo.tomlfiles gainexclude = ["tests/", "examples/", "benches/"].Why now
core/tests/fixtures/holds four PEM files — two RSA private keys, one EC private key, one public key — that the unit tests, the conformance suites andcore/examples/dpop_roundtrip.rsload throughinclude_str!. They are test material: nothing in the SDK verifies against them, and they are namedtest-*.But
cargo package --listshowed all four shipping inside theauthplane-sdktarball, and a crates.io version is immutable — it can be yanked, never deleted. Whatever0.1.0carries, it carries permanently, into everycargo vendor, SBOM and downstream secret scan. Before the first publish is the only cheap moment to decide this.Why
examples/goes withtests/dpop_roundtrip.rsreadstests/fixtures/test-private.pemand hardcodes the matching RSA modulus as a literal, so it is bound to that exact key pair. Excluding the fixture while shipping the example would leave the example unbuildable from the tarball. Both stay in the repository, which is where anyone reading an example is already looking.The alternative — rewriting the ~10
include_str!sites to generate keys in-test, which is what the other SDKs in the family do — is a change to the scaffolding that proves DPoP and JWS behaviour. That belongs in its own PR, not on the path to the first release.Verification
cargo package -p authplane-sdkbuilds and verifies clean;tar tzfon the result finds no.pem.cargo fmt --checkclean, fullcargo testgreen from a checkout — the suites are unaffected, they read the fixtures from the working tree as before.authplane-mcpandauthplane-fastmcpcannot be packaged yet: they resolveauthplane-sdkfrom the crates.io index, which does not have it. That is pre-existing and expected — it is the publish orderRELEASE_SETUP.md§4 prescribes, andpublish-crates.ymlalready waits for the index between crates.