mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 08:27:36 +00:00
rebrand and small tweeks
This commit is contained in:
@@ -32,7 +32,7 @@ import (
|
|||||||
"github.com/spf13/viper"
|
"github.com/spf13/viper"
|
||||||
)
|
)
|
||||||
|
|
||||||
//go:embed gitleaks.toml
|
//go:embed infisical-scan.toml
|
||||||
var DefaultConfig string
|
var DefaultConfig string
|
||||||
|
|
||||||
// use to keep track of how many configs we can extend
|
// use to keep track of how many configs we can extend
|
||||||
@@ -41,6 +41,10 @@ var extendDepth int
|
|||||||
|
|
||||||
const maxExtendDepth = 2
|
const maxExtendDepth = 2
|
||||||
|
|
||||||
|
const DefaultScanConfigFileName = ".infisical-scan.toml"
|
||||||
|
const DefaultScanConfigEnvName = "INFISICAL_SCAN_CONFIG"
|
||||||
|
const DefaultInfisicalIgnoreFineName = ".infisicalignore"
|
||||||
|
|
||||||
// ViperConfig is the config struct used by the Viper config package
|
// ViperConfig is the config struct used by the Viper config package
|
||||||
// to parse the config file. This struct does not include regular expressions.
|
// to parse the config file. This struct does not include regular expressions.
|
||||||
// It is used as an intermediary to convert the Viper config to the Config struct.
|
// It is used as an intermediary to convert the Viper config to the Config struct.
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ title = "gitleaks config"
|
|||||||
[allowlist]
|
[allowlist]
|
||||||
description = "global allow lists"
|
description = "global allow lists"
|
||||||
paths = [
|
paths = [
|
||||||
'''gitleaks.toml''',
|
'''infisical-scan.toml''',
|
||||||
'''(.*?)(jpg|gif|doc|docx|zip|xls|pdf|bin|svg|socket)$''',
|
'''(.*?)(jpg|gif|doc|docx|zip|xls|pdf|bin|svg|socket)$''',
|
||||||
'''(go.mod|go.sum)$''',
|
'''(go.mod|go.sum)$''',
|
||||||
'''gradle.lockfile''',
|
'''gradle.lockfile''',
|
||||||
@@ -58,7 +58,7 @@ const (
|
|||||||
ProtectType
|
ProtectType
|
||||||
ProtectStagedType
|
ProtectStagedType
|
||||||
|
|
||||||
gitleaksAllowSignature = "gitleaks:allow"
|
gitleaksAllowSignature = "infisical-scan:ignore"
|
||||||
)
|
)
|
||||||
|
|
||||||
// Detector is the main detector struct
|
// Detector is the main detector struct
|
||||||
|
|||||||
@@ -54,7 +54,7 @@ func TestDetect(t *testing.T) {
|
|||||||
{
|
{
|
||||||
cfgName: "simple",
|
cfgName: "simple",
|
||||||
fragment: Fragment{
|
fragment: Fragment{
|
||||||
Raw: `awsToken := \"AKIALALEMEL33243OKIA\ // gitleaks:allow"`,
|
Raw: `awsToken := \"AKIALALEMEL33243OKIA\ // infisical-scan:ignore"`,
|
||||||
FilePath: "tmp.go",
|
FilePath: "tmp.go",
|
||||||
},
|
},
|
||||||
expectedFindings: []report.Finding{},
|
expectedFindings: []report.Finding{},
|
||||||
@@ -64,7 +64,7 @@ func TestDetect(t *testing.T) {
|
|||||||
fragment: Fragment{
|
fragment: Fragment{
|
||||||
Raw: `awsToken := \
|
Raw: `awsToken := \
|
||||||
|
|
||||||
\"AKIALALEMEL33243OKIA\ // gitleaks:allow"
|
\"AKIALALEMEL33243OKIA\ // infisical-scan:ignore"
|
||||||
|
|
||||||
`,
|
`,
|
||||||
FilePath: "tmp.go",
|
FilePath: "tmp.go",
|
||||||
@@ -76,7 +76,7 @@ func TestDetect(t *testing.T) {
|
|||||||
fragment: Fragment{
|
fragment: Fragment{
|
||||||
Raw: `awsToken := \"AKIALALEMEL33243OKIA\"
|
Raw: `awsToken := \"AKIALALEMEL33243OKIA\"
|
||||||
|
|
||||||
// gitleaks:allow"
|
// infisical-scan:ignore"
|
||||||
|
|
||||||
`,
|
`,
|
||||||
FilePath: "tmp.go",
|
FilePath: "tmp.go",
|
||||||
|
|||||||
+34
-32
@@ -38,16 +38,16 @@ import (
|
|||||||
|
|
||||||
const configDescription = `config file path
|
const configDescription = `config file path
|
||||||
order of precedence:
|
order of precedence:
|
||||||
1. --config/-c
|
1. --config flag
|
||||||
2. env var GITLEAKS_CONFIG
|
2. env var INFISICAL_SCAN_CONFIG
|
||||||
3. (--source/-s)/.gitleaks.toml
|
3. (--source/-s)/.infisical-scan.toml
|
||||||
If none of the three options are used, then gitleaks will use the default config`
|
If none of the three options are used, then Infisical will use the default scan config`
|
||||||
|
|
||||||
func init() {
|
func init() {
|
||||||
// scan flag for only scan command
|
// scan flag for only scan command
|
||||||
scanCmd.Flags().String("log-opts", "", "git log options")
|
scanCmd.Flags().String("log-opts", "", "git log options")
|
||||||
scanCmd.Flags().Bool("no-git", false, "treat git repo as a regular directory and scan those files, --log-opts has no effect on the scan when --no-git is set")
|
scanCmd.Flags().Bool("no-git", false, "treat git repo as a regular directory and scan those files, --log-opts has no effect on the scan when --no-git is set")
|
||||||
scanCmd.Flags().Bool("pipe", false, "scan input from stdin, ex: `cat some_file | gitleaks detect --pipe`")
|
scanCmd.Flags().Bool("pipe", false, "scan input from stdin, ex: `cat some_file | infisical scan --pipe`")
|
||||||
scanCmd.Flags().Bool("follow-symlinks", false, "scan files that are symlinks to other files")
|
scanCmd.Flags().Bool("follow-symlinks", false, "scan files that are symlinks to other files")
|
||||||
|
|
||||||
// global scan flags
|
// global scan flags
|
||||||
@@ -75,9 +75,6 @@ func init() {
|
|||||||
// add flags to main
|
// add flags to main
|
||||||
scanCmd.AddCommand(scanGitChangesCmd)
|
scanCmd.AddCommand(scanGitChangesCmd)
|
||||||
rootCmd.AddCommand(scanCmd)
|
rootCmd.AddCommand(scanCmd)
|
||||||
|
|
||||||
// Hide flags
|
|
||||||
scanCmd.PersistentFlags().MarkHidden("config")
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func initScanConfig(cmd *cobra.Command) {
|
func initScanConfig(cmd *cobra.Command) {
|
||||||
@@ -85,13 +82,14 @@ func initScanConfig(cmd *cobra.Command) {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
log.Fatal().Msg(err.Error())
|
log.Fatal().Msg(err.Error())
|
||||||
}
|
}
|
||||||
|
|
||||||
if cfgPath != "" {
|
if cfgPath != "" {
|
||||||
viper.SetConfigFile(cfgPath)
|
viper.SetConfigFile(cfgPath)
|
||||||
log.Debug().Msgf("using gitleaks config %s from `--config`", cfgPath)
|
log.Debug().Msgf("using scan config %s from `--config`", cfgPath)
|
||||||
} else if os.Getenv("GITLEAKS_CONFIG") != "" {
|
} else if os.Getenv(config.DefaultScanConfigEnvName) != "" {
|
||||||
envPath := os.Getenv("GITLEAKS_CONFIG")
|
envPath := os.Getenv(config.DefaultScanConfigEnvName)
|
||||||
viper.SetConfigFile(envPath)
|
viper.SetConfigFile(envPath)
|
||||||
log.Debug().Msgf("using gitleaks config from GITLEAKS_CONFIG env var: %s", envPath)
|
log.Debug().Msgf("using scan config from %s env var: %s", config.DefaultScanConfigEnvName, envPath)
|
||||||
} else {
|
} else {
|
||||||
source, err := cmd.Flags().GetString("source")
|
source, err := cmd.Flags().GetString("source")
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -103,8 +101,8 @@ func initScanConfig(cmd *cobra.Command) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if !fileInfo.IsDir() {
|
if !fileInfo.IsDir() {
|
||||||
log.Debug().Msgf("unable to load gitleaks config from %s since --source=%s is a file, using default config",
|
log.Debug().Msgf("unable to load scan config from %s since --source=%s is a file, using default config",
|
||||||
filepath.Join(source, ".gitleaks.toml"), source)
|
filepath.Join(source, config.DefaultScanConfigFileName), source)
|
||||||
viper.SetConfigType("toml")
|
viper.SetConfigType("toml")
|
||||||
if err = viper.ReadConfig(strings.NewReader(config.DefaultConfig)); err != nil {
|
if err = viper.ReadConfig(strings.NewReader(config.DefaultConfig)); err != nil {
|
||||||
log.Fatal().Msgf("err reading toml %s", err.Error())
|
log.Fatal().Msgf("err reading toml %s", err.Error())
|
||||||
@@ -112,23 +110,23 @@ func initScanConfig(cmd *cobra.Command) {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
if _, err := os.Stat(filepath.Join(source, ".gitleaks.toml")); os.IsNotExist(err) {
|
if _, err := os.Stat(filepath.Join(source, config.DefaultScanConfigFileName)); os.IsNotExist(err) {
|
||||||
log.Debug().Msgf("no gitleaks config found in path %s, using default gitleaks config", filepath.Join(source, ".gitleaks.toml"))
|
log.Debug().Msgf("no scan config found in path %s, using default scan config", filepath.Join(source, config.DefaultScanConfigFileName))
|
||||||
viper.SetConfigType("toml")
|
viper.SetConfigType("toml")
|
||||||
if err = viper.ReadConfig(strings.NewReader(config.DefaultConfig)); err != nil {
|
if err = viper.ReadConfig(strings.NewReader(config.DefaultConfig)); err != nil {
|
||||||
log.Fatal().Msgf("err reading default config toml %s", err.Error())
|
log.Fatal().Msgf("err reading default scan config toml %s", err.Error())
|
||||||
}
|
}
|
||||||
return
|
return
|
||||||
} else {
|
} else {
|
||||||
log.Debug().Msgf("using existing gitleaks config %s from `(--source)/.gitleaks.toml`", filepath.Join(source, ".gitleaks.toml"))
|
log.Debug().Msgf("using existing scan config %s from `(--source)/%s`", filepath.Join(source, config.DefaultScanConfigFileName), config.DefaultScanConfigFileName)
|
||||||
}
|
}
|
||||||
|
|
||||||
viper.AddConfigPath(source)
|
viper.AddConfigPath(source)
|
||||||
viper.SetConfigName(".gitleaks")
|
viper.SetConfigName(config.DefaultScanConfigFileName)
|
||||||
viper.SetConfigType("toml")
|
viper.SetConfigType("toml")
|
||||||
}
|
}
|
||||||
if err := viper.ReadInConfig(); err != nil {
|
if err := viper.ReadInConfig(); err != nil {
|
||||||
log.Fatal().Msgf("unable to load gitleaks config, err: %s", err)
|
log.Fatal().Msgf("unable to load scan config, err: %s", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -167,10 +165,10 @@ var scanCmd = &cobra.Command{
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
log.Fatal().Err(err).Msg("")
|
log.Fatal().Err(err).Msg("")
|
||||||
}
|
}
|
||||||
// if config path is not set, then use the {source}/.gitleaks.toml path.
|
// if config path is not set, then use the {source}/.infisical-scan.toml path.
|
||||||
// note that there may not be a `{source}/.gitleaks.toml` file, this is ok.
|
// note that there may not be a `{source}/.infisical-scan.toml` file, this is ok.
|
||||||
if detector.Config.Path == "" {
|
if detector.Config.Path == "" {
|
||||||
detector.Config.Path = filepath.Join(source, ".gitleaks.toml")
|
detector.Config.Path = filepath.Join(source, config.DefaultScanConfigFileName)
|
||||||
}
|
}
|
||||||
// set verbose flag
|
// set verbose flag
|
||||||
if detector.Verbose, err = cmd.Flags().GetBool("verbose"); err != nil {
|
if detector.Verbose, err = cmd.Flags().GetBool("verbose"); err != nil {
|
||||||
@@ -188,8 +186,8 @@ var scanCmd = &cobra.Command{
|
|||||||
log.Fatal().Err(err).Msg("")
|
log.Fatal().Err(err).Msg("")
|
||||||
}
|
}
|
||||||
|
|
||||||
if fileExists(filepath.Join(source, ".infisicalignore")) {
|
if fileExists(filepath.Join(source, config.DefaultInfisicalIgnoreFineName)) {
|
||||||
if err = detector.AddGitleaksIgnore(filepath.Join(source, ".infisicalignore")); err != nil {
|
if err = detector.AddGitleaksIgnore(filepath.Join(source, config.DefaultInfisicalIgnoreFineName)); err != nil {
|
||||||
log.Fatal().Err(err).Msg("could not call AddInfisicalIgnore")
|
log.Fatal().Err(err).Msg("could not call AddInfisicalIgnore")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -199,7 +197,7 @@ var scanCmd = &cobra.Command{
|
|||||||
if baselinePath != "" {
|
if baselinePath != "" {
|
||||||
err = detector.AddBaseline(baselinePath, source)
|
err = detector.AddBaseline(baselinePath, source)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.Error().Msgf("Could not load baseline. The path must point of a gitleaks report generated using the default format: %s", err)
|
log.Error().Msgf("Could not load baseline. The path must point to report generated by `infisical scan` using the default format: %s", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -226,6 +224,8 @@ var scanCmd = &cobra.Command{
|
|||||||
log.Fatal().Err(err)
|
log.Fatal().Err(err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
log.Info().Msgf("scanning for exposed secrets...")
|
||||||
|
|
||||||
// start the detector scan
|
// start the detector scan
|
||||||
if noGit {
|
if noGit {
|
||||||
findings, err = detector.DetectFiles(source)
|
findings, err = detector.DetectFiles(source)
|
||||||
@@ -320,10 +320,10 @@ var scanGitChangesCmd = &cobra.Command{
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
log.Fatal().Err(err).Msg("")
|
log.Fatal().Err(err).Msg("")
|
||||||
}
|
}
|
||||||
// if config path is not set, then use the {source}/.gitleaks.toml path.
|
// if config path is not set, then use the {source}/.infisical-scan.toml path.
|
||||||
// note that there may not be a `{source}/.gitleaks.toml` file, this is ok.
|
// note that there may not be a `{source}/.infisical-scan.toml` file, this is ok.
|
||||||
if detector.Config.Path == "" {
|
if detector.Config.Path == "" {
|
||||||
detector.Config.Path = filepath.Join(source, ".gitleaks.toml")
|
detector.Config.Path = filepath.Join(source, config.DefaultScanConfigFileName)
|
||||||
}
|
}
|
||||||
// set verbose flag
|
// set verbose flag
|
||||||
if detector.Verbose, err = cmd.Flags().GetBool("verbose"); err != nil {
|
if detector.Verbose, err = cmd.Flags().GetBool("verbose"); err != nil {
|
||||||
@@ -341,8 +341,8 @@ var scanGitChangesCmd = &cobra.Command{
|
|||||||
log.Fatal().Err(err).Msg("")
|
log.Fatal().Err(err).Msg("")
|
||||||
}
|
}
|
||||||
|
|
||||||
if fileExists(filepath.Join(source, ".infisicalignore")) {
|
if fileExists(filepath.Join(source, config.DefaultInfisicalIgnoreFineName)) {
|
||||||
if err = detector.AddGitleaksIgnore(filepath.Join(source, ".infisicalignore")); err != nil {
|
if err = detector.AddGitleaksIgnore(filepath.Join(source, config.DefaultInfisicalIgnoreFineName)); err != nil {
|
||||||
log.Fatal().Err(err).Msg("could not call AddInfisicalIgnore")
|
log.Fatal().Err(err).Msg("could not call AddInfisicalIgnore")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -353,6 +353,8 @@ var scanGitChangesCmd = &cobra.Command{
|
|||||||
log.Fatal().Err(err).Msg("")
|
log.Fatal().Err(err).Msg("")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
log.Info().Msgf("scanning for exposed secrets...")
|
||||||
|
|
||||||
// start git scan
|
// start git scan
|
||||||
var findings []report.Finding
|
var findings []report.Finding
|
||||||
if staged {
|
if staged {
|
||||||
@@ -387,7 +389,7 @@ var scanGitChangesCmd = &cobra.Command{
|
|||||||
}
|
}
|
||||||
|
|
||||||
func fileExists(fileName string) bool {
|
func fileExists(fileName string) bool {
|
||||||
// check for a .gitleaksignore file
|
// check for a .infisicalignore file
|
||||||
info, err := os.Stat(fileName)
|
info, err := os.Stat(fileName)
|
||||||
if err != nil && !os.IsNotExist(err) {
|
if err != nil && !os.IsNotExist(err) {
|
||||||
return false
|
return false
|
||||||
|
|||||||
Reference in New Issue
Block a user