mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 09:27:50 +00:00
Small fixes
This commit is contained in:
@@ -57,3 +57,4 @@ yarn-error.log*
|
|||||||
|
|
||||||
# Infisical init
|
# Infisical init
|
||||||
.infisical.json
|
.infisical.json
|
||||||
|
.vscode
|
||||||
@@ -4,7 +4,7 @@ import { tmpdir } from "os";
|
|||||||
import { join } from "path"
|
import { join } from "path"
|
||||||
import { SecretMatch } from "./types";
|
import { SecretMatch } from "./types";
|
||||||
|
|
||||||
export async function scanFullContentAndGetFindings(octokit: any, installationId: number, repositoryFullName: string): Promise<SecretMatch[]> {
|
export async function scanFullRepoContentAndGetFindings(octokit: any, installationId: number, repositoryFullName: string): Promise<SecretMatch[]> {
|
||||||
const tempFolder = await createTempFolder();
|
const tempFolder = await createTempFolder();
|
||||||
const findingsPath = join(tempFolder, "findings.json");
|
const findingsPath = join(tempFolder, "findings.json");
|
||||||
const repoPath = join(tempFolder, "repo.git")
|
const repoPath = join(tempFolder, "repo.git")
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ import { sendMail } from "../../helpers";
|
|||||||
import GitRisks from "../../ee/models/gitRisks";
|
import GitRisks from "../../ee/models/gitRisks";
|
||||||
import { MembershipOrg, User } from "../../models";
|
import { MembershipOrg, User } from "../../models";
|
||||||
import { ADMIN, OWNER } from "../../variables";
|
import { ADMIN, OWNER } from "../../variables";
|
||||||
import { convertKeysToLowercase, scanFullContentAndGetFindings } from "../../ee/services/GithubSecretScanning/helper";
|
import { convertKeysToLowercase, scanFullRepoContentAndGetFindings } from "../../ee/services/GithubSecretScanning/helper";
|
||||||
import { getSecretScanningGitAppId, getSecretScanningPrivateKey } from "../../config";
|
import { getSecretScanningGitAppId, getSecretScanningPrivateKey } from "../../config";
|
||||||
import { SecretMatch } from "../../ee/services/GithubSecretScanning/types";
|
import { SecretMatch } from "../../ee/services/GithubSecretScanning/types";
|
||||||
|
|
||||||
@@ -22,6 +22,7 @@ type TScanPushEventQueueDetails = {
|
|||||||
|
|
||||||
githubFullRepositorySecretScan.process(async (job: Job, done: Queue.DoneCallback) => {
|
githubFullRepositorySecretScan.process(async (job: Job, done: Queue.DoneCallback) => {
|
||||||
const { organizationId, repository, installationId }: TScanPushEventQueueDetails = job.data
|
const { organizationId, repository, installationId }: TScanPushEventQueueDetails = job.data
|
||||||
|
try {
|
||||||
const octokit = new ProbotOctokit({
|
const octokit = new ProbotOctokit({
|
||||||
auth: {
|
auth: {
|
||||||
appId: await getSecretScanningGitAppId(),
|
appId: await getSecretScanningGitAppId(),
|
||||||
@@ -29,9 +30,7 @@ githubFullRepositorySecretScan.process(async (job: Job, done: Queue.DoneCallback
|
|||||||
installationId: installationId
|
installationId: installationId
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
try {
|
const findings : SecretMatch[] = await scanFullRepoContentAndGetFindings(octokit, installationId, repository.fullName)
|
||||||
const findings : SecretMatch[] = await scanFullContentAndGetFindings(octokit, installationId, repository.fullName)
|
|
||||||
|
|
||||||
for (const finding of findings) {
|
for (const finding of findings) {
|
||||||
await GitRisks.findOneAndUpdate({ fingerprint: finding.Fingerprint},
|
await GitRisks.findOneAndUpdate({ fingerprint: finding.Fingerprint},
|
||||||
{
|
{
|
||||||
@@ -84,10 +83,9 @@ try {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
done(null, findings)
|
done(null, findings)
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
done(new Error(`gitHubHistoricalScanning.process: an error occurred ${error}`), null)
|
done(new Error(`gitHubHistoricalScanning.process: an error occurred ${error}`), null)
|
||||||
}
|
}
|
||||||
|
|
||||||
})
|
})
|
||||||
|
|
||||||
export const scanGithubFullRepoForSecretLeaks = (pushEventPayload: TScanPushEventQueueDetails) => {
|
export const scanGithubFullRepoForSecretLeaks = (pushEventPayload: TScanPushEventQueueDetails) => {
|
||||||
|
|||||||
Reference in New Issue
Block a user