mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 23:27:35 +00:00
Small fixes
This commit is contained in:
@@ -57,3 +57,4 @@ yarn-error.log*
|
|||||||
|
|
||||||
# Infisical init
|
# Infisical init
|
||||||
.infisical.json
|
.infisical.json
|
||||||
|
.vscode
|
||||||
@@ -4,7 +4,7 @@ import { tmpdir } from "os";
|
|||||||
import { join } from "path"
|
import { join } from "path"
|
||||||
import { SecretMatch } from "./types";
|
import { SecretMatch } from "./types";
|
||||||
|
|
||||||
export async function scanFullContentAndGetFindings(octokit: any, installationId: number, repositoryFullName: string): Promise<SecretMatch[]> {
|
export async function scanFullRepoContentAndGetFindings(octokit: any, installationId: number, repositoryFullName: string): Promise<SecretMatch[]> {
|
||||||
const tempFolder = await createTempFolder();
|
const tempFolder = await createTempFolder();
|
||||||
const findingsPath = join(tempFolder, "findings.json");
|
const findingsPath = join(tempFolder, "findings.json");
|
||||||
const repoPath = join(tempFolder, "repo.git")
|
const repoPath = join(tempFolder, "repo.git")
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ import { sendMail } from "../../helpers";
|
|||||||
import GitRisks from "../../ee/models/gitRisks";
|
import GitRisks from "../../ee/models/gitRisks";
|
||||||
import { MembershipOrg, User } from "../../models";
|
import { MembershipOrg, User } from "../../models";
|
||||||
import { ADMIN, OWNER } from "../../variables";
|
import { ADMIN, OWNER } from "../../variables";
|
||||||
import { convertKeysToLowercase, scanFullContentAndGetFindings } from "../../ee/services/GithubSecretScanning/helper";
|
import { convertKeysToLowercase, scanFullRepoContentAndGetFindings } from "../../ee/services/GithubSecretScanning/helper";
|
||||||
import { getSecretScanningGitAppId, getSecretScanningPrivateKey } from "../../config";
|
import { getSecretScanningGitAppId, getSecretScanningPrivateKey } from "../../config";
|
||||||
import { SecretMatch } from "../../ee/services/GithubSecretScanning/types";
|
import { SecretMatch } from "../../ee/services/GithubSecretScanning/types";
|
||||||
|
|
||||||
@@ -22,72 +22,70 @@ type TScanPushEventQueueDetails = {
|
|||||||
|
|
||||||
githubFullRepositorySecretScan.process(async (job: Job, done: Queue.DoneCallback) => {
|
githubFullRepositorySecretScan.process(async (job: Job, done: Queue.DoneCallback) => {
|
||||||
const { organizationId, repository, installationId }: TScanPushEventQueueDetails = job.data
|
const { organizationId, repository, installationId }: TScanPushEventQueueDetails = job.data
|
||||||
const octokit = new ProbotOctokit({
|
try {
|
||||||
auth: {
|
const octokit = new ProbotOctokit({
|
||||||
appId: await getSecretScanningGitAppId(),
|
auth: {
|
||||||
privateKey: await getSecretScanningPrivateKey(),
|
appId: await getSecretScanningGitAppId(),
|
||||||
installationId: installationId
|
privateKey: await getSecretScanningPrivateKey(),
|
||||||
},
|
installationId: installationId
|
||||||
});
|
},
|
||||||
try {
|
});
|
||||||
const findings : SecretMatch[] = await scanFullContentAndGetFindings(octokit, installationId, repository.fullName)
|
const findings : SecretMatch[] = await scanFullRepoContentAndGetFindings(octokit, installationId, repository.fullName)
|
||||||
|
for (const finding of findings) {
|
||||||
for (const finding of findings) {
|
await GitRisks.findOneAndUpdate({ fingerprint: finding.Fingerprint},
|
||||||
await GitRisks.findOneAndUpdate({ fingerprint: finding.Fingerprint},
|
{
|
||||||
{
|
|
||||||
...convertKeysToLowercase(finding),
|
...convertKeysToLowercase(finding),
|
||||||
installationId: installationId,
|
installationId: installationId,
|
||||||
organization: organizationId,
|
organization: organizationId,
|
||||||
repositoryFullName: repository.fullName,
|
repositoryFullName: repository.fullName,
|
||||||
repositoryId: repository.id
|
repositoryId: repository.id
|
||||||
}, {
|
}, {
|
||||||
upsert: true
|
upsert: true
|
||||||
}).lean()
|
}).lean()
|
||||||
}
|
|
||||||
|
|
||||||
// get emails of admins
|
|
||||||
const adminsOfWork = await MembershipOrg.find({
|
|
||||||
organization: organizationId,
|
|
||||||
$or: [
|
|
||||||
{ role: OWNER },
|
|
||||||
{ role: ADMIN }
|
|
||||||
]
|
|
||||||
}).lean()
|
|
||||||
|
|
||||||
const userEmails = await User.find({
|
|
||||||
_id: {
|
|
||||||
$in: [adminsOfWork.map(orgMembership => orgMembership.user)]
|
|
||||||
}
|
}
|
||||||
}).select("email").lean()
|
|
||||||
|
|
||||||
const usersToNotify = userEmails.map(userObject => userObject.email)
|
// get emails of admins
|
||||||
|
const adminsOfWork = await MembershipOrg.find({
|
||||||
|
organization: organizationId,
|
||||||
|
$or: [
|
||||||
|
{ role: OWNER },
|
||||||
|
{ role: ADMIN }
|
||||||
|
]
|
||||||
|
}).lean()
|
||||||
|
|
||||||
if (findings.length) {
|
const userEmails = await User.find({
|
||||||
await sendMail({
|
_id: {
|
||||||
template: "historicalSecretLeakIncident.handlebars",
|
$in: [adminsOfWork.map(orgMembership => orgMembership.user)]
|
||||||
subjectLine: `Incident alert: leaked secrets found in Github repository ${repository.fullName}`,
|
|
||||||
recipients: usersToNotify,
|
|
||||||
substitutions: {
|
|
||||||
numberOfSecrets: findings.length,
|
|
||||||
}
|
}
|
||||||
});
|
}).select("email").lean()
|
||||||
}
|
|
||||||
|
|
||||||
const postHogClient = await TelemetryService.getPostHogClient();
|
const usersToNotify = userEmails.map(userObject => userObject.email)
|
||||||
if (postHogClient) {
|
|
||||||
postHogClient.capture({
|
if (findings.length) {
|
||||||
event: "historical cloud secret scan",
|
await sendMail({
|
||||||
distinctId: repository.fullName,
|
template: "historicalSecretLeakIncident.handlebars",
|
||||||
properties: {
|
subjectLine: `Incident alert: leaked secrets found in Github repository ${repository.fullName}`,
|
||||||
numberOfRisksFound: findings.length,
|
recipients: usersToNotify,
|
||||||
}
|
substitutions: {
|
||||||
});
|
numberOfSecrets: findings.length,
|
||||||
}
|
}
|
||||||
done(null, findings)
|
});
|
||||||
} catch (error) {
|
}
|
||||||
|
|
||||||
|
const postHogClient = await TelemetryService.getPostHogClient();
|
||||||
|
if (postHogClient) {
|
||||||
|
postHogClient.capture({
|
||||||
|
event: "historical cloud secret scan",
|
||||||
|
distinctId: repository.fullName,
|
||||||
|
properties: {
|
||||||
|
numberOfRisksFound: findings.length,
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
done(null, findings)
|
||||||
|
} catch (error) {
|
||||||
done(new Error(`gitHubHistoricalScanning.process: an error occurred ${error}`), null)
|
done(new Error(`gitHubHistoricalScanning.process: an error occurred ${error}`), null)
|
||||||
}
|
}
|
||||||
|
|
||||||
})
|
})
|
||||||
|
|
||||||
export const scanGithubFullRepoForSecretLeaks = (pushEventPayload: TScanPushEventQueueDetails) => {
|
export const scanGithubFullRepoForSecretLeaks = (pushEventPayload: TScanPushEventQueueDetails) => {
|
||||||
|
|||||||
Reference in New Issue
Block a user