feature: secret scanning pt2 and address initial feedback

This commit is contained in:
Scott Wilson
2025-05-29 20:40:48 -07:00
parent e6c97510ca
commit 4773336a04
78 changed files with 1038 additions and 346 deletions

View File

@@ -0,0 +1,91 @@
import {Tabs} from "../../../../frontend/src/components/v2";## Prerequisites
- Create a [GitHub Radar Connection](/integrations/app-connections/github-radar)
## Create a GitHub Data Source in Infisical
<Tabs>
<Tab title="Infisical UI">
1. Navigate to your Secret Scanning Project's Dashboard and click the **Add Data Source** button.
![Secret Scanning Dashboard](/images/platform/secret-scanning/github/github-data-source-step-1.png)
2. Select the **GitHub** option.
![Select GitHub Option](/images/platform/secret-scanning/github/github-data-source-step-2.png)
3. Select the **GitHub Radar Connection** to use and configure which repositories you would like to scan. Then click **Next**.
![Data Source Configuration](/images/platform/secret-scanning/github/github-data-source-step-3.png)
- **GitHub Radar Connection** - the connection that has access to the repositories you want to scan.
- **Scan Repositories** - select which repositories you would like to scan.
- **All Repositories** - Infisical will scan all repositories associated with your connection.
- **Select Repositories** - Infisical will scan the selected repositories.
- **Auto-Scan Enabled** - whether Infisical should automatically perform a scan when a push is made to configured repositories.
4. Give your data source a name and description (optional). Then click **Next**.
![Data Source Details](/images/platform/secret-scanning/github/github-data-source-step-4.png)
- **Name** - the name of the data source. Must be slug-friendly.
- **Description** (optional) - a description of this rotation configuration.
5. Review your data source, then click **Create Data Source**.
![Data Source Review](/images/platform/secret-scanning/github/github-data-source-step-5.png)
6. Your **GitHub Data Source** is now available and will begin a full scan if **Auto-Scan** is enabled.
![Data Source Created](/images/platform/secret-scanning/github/github-data-source-step-6.png)
7. You can view repositories and scan results by clicking on your data source.
![Data Source Page](/images/platform/secret-scanning/github/github-data-source-step-7.png)
8. In addition, you can review any findings from the **Findings Page**.
![Findings Page](/images/platform/secret-scanning/github/github-data-source-step-8.png)
</Tab>
<Tab title="API">
To create a GitHub Data Source, make an API request to the [Create GitHub Data Source](/api-reference/endpoints/secret-scanning/data-sources/github/create) API endpoint.
### Sample request
```bash Request
curl --request POST \
--url https://us.infisical.com/api/v2/secret-scanning/data-sources/github \
--header 'Content-Type: application/json' \
--data '{
"name": "my-github-source",
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"description": "my github data source",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"isAutoScanEnabled": true,
"rotationInterval": 30,
"config": {
"includeRepos": ["*"],
}
}'
```
### Sample response
```bash Response
{
"dataSource": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"externalId": "1234567890",
"name": "my-github-source",
"description": "my github data source",
"isAutoScanEnabled": true,
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"type": "github",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"connection": {
"app": "github-radar",
"name": "my-radar-app",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"config": {
"includeRepos": ["*"]
}
}
}
```
</Tab>
</Tabs>

View File

@@ -29,7 +29,7 @@ Data sources are configured integrations with external platforms, such as a GitH
A data source acts as a secure intermediary between the external system and the scanner engine. It manages a collection of scannable resources (such as repositories) and handles the authentication and communication required for scanning operations.
[data source page image]
![data sources](/images/platform/secret-scanning/secret-scanning-data-sources.png)
### Resources
@@ -37,15 +37,13 @@ Resources are the atomic, scannable units, such as a repository, that can be mon
Each resource maintains its own scanning history and status, allowing for granular monitoring and management of secret scanning across your organization.
[resource table image]
![resources](/images/platform/secret-scanning/secret-scanning-resources.png)
### Scans
Scans can be initiated in two ways:
1. **Full Scan** - Manually triggered scan that comprehensively checks either:
- All resources associated with a data source
- A single selected resource
1. **Full Scan** - Manually triggered scan that comprehensively checks either all resources associated with a data source or a single selected resource.
2. **Diff Scan** - Automatically executed when **Auto-Scan** is enabled on a data source. This scan type specifically focuses on updates to existing resources.
@@ -55,42 +53,23 @@ All scan activities can be monitored in real-time through the Infisical UI, whic
- Resource(s) being scanned
- Detection results (whether any secrets were found)
[scan table image]
![scans](/images/platform/secret-scanning/secret-scanning-scans.png)
## [In Progress - old below]
### Findings
## Code Scanning
Findings are automatically generated when secret leaks are detected during scanning operations. Each finding contains comprehensive information including:
- The specific scanning rule that identified the leak
- File location and line number where the secret was found
- Resource-specific details (e.g., commit hash and author for Git repositories)
![Scanning Overview](/images/platform/secret-scanning/overview.png)
Findings are initially marked as **Unresolved** and can be updated to one of the following statuses with additional remarks:
- **Resolved** - The issue has been addressed
- **False Positive** - The detection was incorrect
- **Ignore** - The finding can be safely disregarded
Secret scans are built on event-driven architecture. This means that every time a push is made to one of your selected repositories, Infisical will scan the modified files for any exposed secrets.
These status options help teams effectively track and manage the lifecycle of detected secret leaks.
If one or more exposed secrets are detected, it will be displayed in your Infisical dashboard. An exposed secret is known as a **"Risk"**. Each risk has the following data associated with it:
- **Date**: When the risk was first detected.
- **Secret Type**: Which type of secret was detected.
- **Info**: Information about the secret, such as the repository, file name, and the committer who made the change.
Once an exposed secret is detected, all organization admins will be sent an e-mail notification containing details about the exposed secret.
<Tip>
Each risk also contains a "View Exposed Secret" button, which will take you directly to the GitHub commit and to the line where the secret was exposed.
</Tip>
![Exposed Secret](/images/platform/secret-scanning/exposed-secret.png)
## Responding to Exposed Secrets
After an exposed secret is detected, it will be marked as `Needs Attention`. When there are risks marked as needs attention, it's important to address them as soon as possible.
You can mark the risk as `Resolved` by changing the status to one of the following states:
- **This Is a False Positive**: The secret was not exposed, but was detected by the scanner.
- **I Have Rotated The Secret**: The secret was exposed, but it has now been removed.
- **No Rotation Needed**: You are choosing to ignore this risk. You may choose to do this if the risk is non-sensitive or otherwise not a security risk.
![Needs Attention](/images/platform/secret-scanning/needs-attention.png)
![findings](/images/platform/secret-scanning/secret-scanning-findings.png)
## Ignoring Known Secrets
If you're intentionally committing a test secret that the secret scanner might flag, you can instruct Infisical to overlook that secret with the methods listed below.