a7bb00d935
Wave B of P03. Adds Go-level tests that verify the security configuration files have the expected shape. We don't run gosec/govulncheck/gitleaks here (they're external binaries installed by .coreci.yml ); instead, the tests catch configuration drift by asserting the right tokens are present in the config files. - internal/security/security_scan_test.go — covers the shape of .gitleaks.toml (cert PEM allowlist present), .gitleaks-baseline.json (valid JSON, skip entries with Commit/File), .golangci.yml (gosec/govet/ineffassign/ misspell enabled), scripts/security_scan.sh (executable, references all three tools + GOFLAGS), and .coreci.yml (gosec/govulncheck/gitleaks stages present, GOFLAGS env, go test -race wired). - internal/security/security_gosec_g101_test.go — meta- tests: the .coreci.yml pipeline installs gosec and runs it; GOFLAGS=-mod=mod is set for offline mode (REQ-027). The fixture file in testdata/ carries a literal G101 pattern that any future CI run will flag if the allowlist is misconfigured. - internal/security/testdata/hardcoded_creds.go — the G101 fixture. The value is intentionally a sentinel prefix (GOSEC_G101_FIXTURE_VALUE_*) that does not match real-secret patterns; gitleaks allowlist for the path keeps it from being a false positive on the secret scanner while still triggering gosec's G101 rule. All builds clean; tests pass with -race; gofmt -l . clean. ---ci--- project: orca phase: 10 milestone: v0.2 status: execute ---/ci---