Skip to content

test(fuzz): add bounded campaigns and fix glob edge cases - #221

Open
swarit-stepsecurity wants to merge 3 commits into
step-security:mainfrom
swarit-stepsecurity:swarit/test/wt/fuzz-coverage
Open

swarit-stepsecurity wants to merge 3 commits into
step-security:mainfrom
swarit-stepsecurity:swarit/test/wt/fuzz-coverage

Conversation

@swarit-stepsecurity

Copy link
Copy Markdown
Member
  • Add bounded fuzzing for rules, package parsers, credential redaction, and scan state. Fix newline and Unicode glob-matching bugs, retain regression inputs, and document the test plan.
  • Run short PR and longer nightly campaigns with failure artifacts. Nine targets passed 3.6 million local executions; race tests, smoke tests, lint, and cross-platform builds passed.

Signed-off-by: Swarit Pandey <swarit@stepsecurity.io>
@swarit-stepsecurity
swarit-stepsecurity marked this pull request as ready for review September 21, 2026 12:48

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Generated hidden log filenames are excluded from failure artifacts by default.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds bounded Go fuzzing across parsers, rules, credentials, and state while fixing Unicode and newline glob matching.

Changes:

  • Adds nine fuzz targets with regression corpora.
  • Introduces PR and nightly fuzz campaigns.
  • Fixes glob matching for Unicode and newline-containing paths.
File Description
tests/​test_fuzz_go.sh Runs bounded fuzz targets and captures logs.
Makefile Adds the fuzz target.
internal/​state/​fuzz_test.go Fuzzes JSON hashing and state transitions.
internal/​detector/​testdata/​fuzz/​FuzzNodeLockfiles/​2547f93cad4792c6 Adds a Node parser regression input.
internal/​detector/​rules/​testdata/​fuzz/​FuzzGlobMatch/​644c784a7038dfed Adds the newline glob regression input.
internal/​detector/​rules/​glob.go Corrects newline and Unicode matching.
internal/​detector/​rules/​fuzz_test.go Fuzzes glob, rule preparation, and screening.
internal/​detector/​rules/​engine_test.go Tests newline-containing directories.
internal/​detector/​fuzz_test.go Fuzzes Node and Python metadata parsers.
internal/​detector/​credentials/​fuzz_test.go Bounds credential parser inputs.
internal/​detector/​configaudit/​fuzz_test.go Fuzzes npm credential redaction.
docs/​fuzzing.md Documents scope, execution, and findings.
.gitignore Ignores local fuzz logs.
.github/​workflows/​fuzz.yml Adds PR and scheduled fuzz campaigns.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tests/test_fuzz_go.sh Outdated
echo "No fuzz targets found in $package" >&2
exit 1
fi
package_label=${package//\//_}

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants