This PR extends the allowed characters in names for secret keys to also include `-` and `_`, allowing keys like `$my-secret-key` which would previously not be matched.
This PR also adds detection of partial matches, so keys that start with the prefix, but do not match are reported as a warning. This could happen if the input key is `$my:secret` because the `:` is not matched. To prevent logging sensitive information, only the number of partial matches is reported, not the values.
It is possible that the user intended for such a value to be a matched key, but it is also possible that this value was meant to be verbatim. We can consider if this should stop the process instead of just emitting a warning, as the user should fix the issue in either case.
The fix for this would be to use the secret provider pattern and change to something that is not partially matched.
This check only verifies that the secret provider is not faulty, as each provider *should* fail if the values cannot be translated.
With this commit it is explicit, so future modules are ensured to function as expected.