Secret scanning docs

This commit is contained in:
x032205
2025-07-03 23:45:05 -04:00
parent 06bd593b60
commit d2c6bcc7a7
21 changed files with 164 additions and 5 deletions

View File

@@ -0,0 +1,4 @@
---
title: "Create"
openapi: "POST /api/v2/secret-scanning/data-sources/bitbucket"
---

View File

@@ -0,0 +1,4 @@
---
title: "Delete"
openapi: "DELETE /api/v2/secret-scanning/data-sources/bitbucket/{dataSourceId}"
---

View File

@@ -0,0 +1,4 @@
---
title: "Get by ID"
openapi: "GET /api/v2/secret-scanning/data-sources/bitbucket/{dataSourceId}"
---

View File

@@ -0,0 +1,4 @@
---
title: "Get by Name"
openapi: "GET /api/v2/secret-scanning/data-sources/bitbucket/data-source-name/{dataSourceName}"
---

View File

@@ -0,0 +1,4 @@
---
title: "List Resources"
openapi: "GET /api/v2/secret-scanning/data-sources/bitbucket/{dataSourceId}/resources"
---

View File

@@ -0,0 +1,4 @@
---
title: "List Scans"
openapi: "GET /api/v2/secret-scanning/data-sources/bitbucket/{dataSourceId}/scans"
---

View File

@@ -0,0 +1,4 @@
---
title: "List"
openapi: "GET /api/v2/secret-scanning/data-sources/bitbucket"
---

View File

@@ -0,0 +1,4 @@
---
title: "Scan Resource"
openapi: "POST /api/v2/secret-scanning/data-sources/bitbucket/{dataSourceId}/resources/{resourceId}/scan"
---

View File

@@ -0,0 +1,4 @@
---
title: "Scan"
openapi: "POST /api/v2/secret-scanning/data-sources/bitbucket/{dataSourceId}/scan"
---

View File

@@ -0,0 +1,4 @@
---
title: "Update"
openapi: "PATCH /api/v2/secret-scanning/data-sources/bitbucket/{dataSourceId}"
---

View File

@@ -210,6 +210,7 @@
"group": "Secret Scanning",
"pages": [
"documentation/platform/secret-scanning/overview",
"documentation/platform/secret-scanning/bitbucket",
"documentation/platform/secret-scanning/github"
]
}
@@ -1111,6 +1112,21 @@
"pages": [
"api-reference/endpoints/secret-scanning/data-sources/list",
"api-reference/endpoints/secret-scanning/data-sources/options",
{
"group": "Bitbucket",
"pages": [
"api-reference/endpoints/secret-scanning/data-sources/bitbucket/list",
"api-reference/endpoints/secret-scanning/data-sources/bitbucket/get-by-id",
"api-reference/endpoints/secret-scanning/data-sources/bitbucket/get-by-name",
"api-reference/endpoints/secret-scanning/data-sources/bitbucket/list-resources",
"api-reference/endpoints/secret-scanning/data-sources/bitbucket/list-scans",
"api-reference/endpoints/secret-scanning/data-sources/bitbucket/create",
"api-reference/endpoints/secret-scanning/data-sources/bitbucket/update",
"api-reference/endpoints/secret-scanning/data-sources/bitbucket/delete",
"api-reference/endpoints/secret-scanning/data-sources/bitbucket/scan",
"api-reference/endpoints/secret-scanning/data-sources/bitbucket/scan-resource"
]
},
{
"group": "GitHub",
"pages": [

View File

@@ -0,0 +1,98 @@
---
title: "Bitbucket Secret Scanning"
sidebarTitle: "Bitbucket"
description: "Learn how to configure secret scanning for Bitbucket."
---
## Prerequisites
- Create a [Bitbucket Connection](/integrations/app-connections/bitbucket)
## Create a Bitbucket Data Source in Infisical
<Tabs>
<Tab title="Infisical UI">
1. Navigate to your Secret Scanning Project's Dashboard and click the **Add Data Source** button.
![Secret Scanning Dashboard](/images/platform/secret-scanning/github/github-data-source-step-1.png)
2. Select the **Bitbucket** option.
3. Configure which workspace and repositories you would like to scan. Then click **Next**.
![Data Source Configuration](/images/platform/secret-scanning/bitbucket/step-3.png)
- **Bitbucket Radar Connection** - the connection that has access to the repositories you want to scan.
- **Workspace** - the Bitbucket workspace to scan secrets in.
- **Scan Repositories** - select which repositories you would like to scan.
- **All Repositories** - Infisical will scan all repositories associated with your connection.
- **Select Repositories** - Infisical will scan the selected repositories.
- **Auto-Scan Enabled** - whether Infisical should automatically perform a scan when a push is made to configured repositories.
4. Give your data source a name and description (optional). Then click **Next**.
![Data Source Details](/images/platform/secret-scanning/bitbucket/step-4.png)
- **Name** - the name of the data source. Must be slug-friendly.
- **Description** (optional) - a description of this data source.
5. Review your data source, then click **Create Data Source**.
![Data Source Review](/images/platform/secret-scanning/bitbucket/step-5.png)
6. Your **Bitbucket Data Source** is now available and will begin a full scan if **Auto-Scan** is enabled.
![Data Source Created](/images/platform/secret-scanning/bitbucket/step-6.png)
7. You can view repositories and scan results by clicking on your data source.
![Data Source Page](/images/platform/secret-scanning/bitbucket/step-7.png)
8. In addition, you can review any findings from the **Findings Page**.
![Findings Page](/images/platform/secret-scanning/bitbucket/step-8.png)
</Tab>
<Tab title="API">
To create a Bitbucket Data Source, make an API request to the [Create Bitbucket Data Source](/api-reference/endpoints/secret-scanning/data-sources/bitbucket/create) API endpoint.
### Sample request
```bash Request
curl --request POST \
--url https://us.infisical.com/api/v2/secret-scanning/data-sources/bitbucket \
--header 'Content-Type: application/json' \
--data '{
"name": "my-bitbucket-source",
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"description": "my bitbucket data source",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"isAutoScanEnabled": true,
"config": {
"workspaceSlug": "my-workspace",
"includeRepos": ["*"]
}
}'
```
### Sample response
```bash Response
{
"dataSource": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"externalId": "1234567890",
"name": "my-bitbucket-source",
"description": "my bitbucket data source",
"isAutoScanEnabled": true,
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"type": "bitbucket",
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"connection": {
"app": "bitbucket",
"name": "my-bitbucket-app",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"config": {
"workspaceSlug": "my-workspace",
"includeRepos": ["*"]
}
}
}
```
</Tab>
</Tabs>

Binary file not shown.

After

Width:  |  Height:  |  Size: 146 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 102 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 91 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 948 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.0 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 MiB

View File

@@ -13,12 +13,13 @@ export const BitbucketDataSourceReviewFields = () => {
}
>();
const [{ includeRepos }, connection] = watch(["config", "connection"]);
const [{ includeRepos, workspaceSlug }, connection] = watch(["config", "connection"]);
const shouldScanAll = includeRepos[0] === "*";
return (
<SecretScanningDataSourceConfigReviewSection>
{connection && <GenericFieldLabel label="Connection">{connection.name}</GenericFieldLabel>}
<GenericFieldLabel label="Workspace Slug">{workspaceSlug}</GenericFieldLabel>
<GenericFieldLabel label="Scan Repositories">
{shouldScanAll ? "All" : includeRepos.join(", ")}
</GenericFieldLabel>

View File

@@ -6,6 +6,7 @@ import { TSecretScanningDataSourceBase } from "./shared";
export type TBitbucketDataSource = TSecretScanningDataSourceBase & {
type: SecretScanningDataSource.Bitbucket;
config: {
workspaceSlug: string;
includeRepos: string[];
};
};

View File

@@ -7,12 +7,15 @@ type Props = {
export const BitbucketDataSourceConfigDisplay = ({ dataSource }: Props) => {
const {
config: { includeRepos }
config: { includeRepos, workspaceSlug }
} = dataSource;
return (
<GenericFieldLabel label="Scan Repositories">
{includeRepos.includes("*") ? "All" : includeRepos.join(", ")}
</GenericFieldLabel>
<>
<GenericFieldLabel label="Workspace Slug">{workspaceSlug}</GenericFieldLabel>
<GenericFieldLabel label="Scan Repositories">
{includeRepos.includes("*") ? "All" : includeRepos.join(", ")}
</GenericFieldLabel>
</>
);
};