Skip to content

Report Clerk secret keys as Clerk, not as Stripe #71

Description

@omerbek

Clerk (a popular auth provider for Next.js apps) also uses sk_live_ / sk_test_ secret keys. Today the Stripe pattern \b(?:sk|rk)_live_[A-Za-z0-9]{20,}\b in repodx.py catches a Clerk live key and reports it as "Stripe secret key", which confuses users who don't use Stripe.

Medium difficulty: this needs a little research, not just one line.

How to do it

  1. Look up both formats in Clerk's and Stripe's docs (length and character set after sk_live_) and find a reliable difference.
  2. Either add a separate ("Clerk secret key", ...) pattern and make sure a key is reported by only one of them, or, if they can't be told apart, rename the finding to a neutral title such as "Secret key (Stripe or Clerk)".
  3. Add tests built with fake(...) for both shapes. Each must produce exactly one finding with the right title.
  4. Run python3 -m unittest discover and python3 repodx.py . (must stay 100/100).

Please describe the format difference you found (with links to the docs) in the PR. Comment here to claim it. One issue per person. See CONTRIBUTING.md. Never paste a real key.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions