"""v1.14 (REQ-146): no credential-looking files are tracked by git.""" import subprocess import sys from pathlib import Path import pytest ROOT = Path(__file__).resolve().parent.parent CREDENTIAL_EXTENSIONS = [".pem", ".key", ".p12", ".pfx", ".cer", ".crt", ".jks", ".keystore"] def test_no_credential_files_tracked(): """Assert no file with a credential extension is tracked by git.""" result = subprocess.run( ["git", "ls-files"], cwd=str(ROOT), capture_output=True, text=True, ) if result.returncode != 0: pytest.skip("git not available or not a repo") tracked = result.stdout.strip().split("\n") cred_files = [ f for f in tracked if any(f.endswith(ext) for ext in CREDENTIAL_EXTENSIONS) ] assert cred_files == [], f"credential files tracked by git: {cred_files}" def test_gitignore_has_credential_patterns(): """Assert .gitignore contains the credential-pattern catch-all.""" gitignore = (ROOT / ".gitignore").read_text() for ext in [".pem", ".key", ".p12", ".pfx"]: assert f"*{ext}" in gitignore, f".gitignore missing credential pattern *{ext}"