Skip to main content

pytest-mask-secrets

pytest-mask-secrets is a plugin for pytest that removes sensitive data from test reports.

Based on the configuration, it searches for specified secrets, passwords, and tokens in the records and replaces them with asterisks.

While this feature is usually provided by CI tools, it can be insufficient in many situations as it only strips secrets from the captured output. A common case of leaking secrets is through generated JUnit files that are not curated by CI tools. Therefore, it is necessary to have such functionality at the pytest level.

Installation

pip install pytest-mask-secrets

Usage

pytest-mask-secrets needs to know which values to mask. These values are read from environment variables. The list of these variables is passed in the MASK_SECRETS environment variable, which contains a comma-separated list of all environment variables containing secrets. Here is an example:

export PYPI_API_TOKEN=mytoken
export SOME_PASSWORD=mypassword
export MASK_SECRETS=PYPI_API_TOKEN,SOME_PASSWORD

pytest

With pytest-mask-secrets installed, all occurrences of "mytoken" and "mypassword" will be eliminated from the report.

Define Secret Values in the Code

Tests can use config.stash to define secret values to be masked. There is a mask_secrets_key available that provides access to a set() where additional secret values can be added. Here is an example:

from pytest_mask_secrets.plugin import mask_secrets_key

def test(pytestconfig):
    pytestconfig.stash[mask_secrets_key].add("true-secret")
    ...

All occurrences of "true-secret" will be removed from the report.

Automagic Identification of Variables with Secrets

If MASK_SECRETS_AUTO is set to anything other than zero ("0"), all environment variables containing the words "TOKEN", "SECRET," "PASSWORD," or "PASSWD" in their names are considered sensitive, and their values are removed from the report.

This discovery mode should be used with caution. CI workflows, in particular, should rely on an explicit list of secret variables. Under certain circumstances, this method can lead to the leakage of other sensitive data (if, by accident, a secret from an environment variable matches text commonly present in the test report). Nevertheless, this method can still be useful for example for local execution to prevent accidental leaks through copy-and-paste.

Release files for pytest-mask-secrets 1.7.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pytest-mask-secrets 1.7.0
File Size Uploaded
pytest_mask_secrets-1.7.0.tar.gz 4.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pytest-mask-secrets 1.7.0
File Interpreter ABI Platform
pytest_mask_secrets-1.7.0-py3-none-any.whl Python 3 none any Details

Total release size: 8.7 kB

Release files / pytest_mask_secrets-1.7.0.tar.gz

Download URL pytest_mask_secrets-1.7.0.tar.gz
Size 4.3 kB
Tags Source
SHA-256 checksum
How to use checksums
fca15b5ddcca823d5dafde83f7111ac14c4e06463693bd831cf5fcfeab83df40
BLAKE2b-256 checksum
How to use checksums
e84f2cbd9a103e529476ce7d52bf999bad41287a31f8eb0a93102e799046d461
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via pdm/2.28.0 CPython/3.12.3 Linux/6.17.0-1020-azure

Release files / pytest_mask_secrets-1.7.0-py3-none-any.whl

Download URL pytest_mask_secrets-1.7.0-py3-none-any.whl
Size 4.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5d476c284dd96b6c75cf098c2fda78b6d6ff70931bf2b1081ea92fa9e38ead97
BLAKE2b-256 checksum
How to use checksums
33b7efeea8aa56fea741cd95856119fac6316ba0713520e8524315cf38ef2203
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via pdm/2.28.0 CPython/3.12.3 Linux/6.17.0-1020-azure

Release history Release notifications | RSS feed

This release

1.7.0 This release

2 release files

1.6.0

2 release files

1.5.0

2 release files

1.4.0

2 release files

1.3.0

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page