This commit is contained in:
@@ -0,0 +1,42 @@
|
||||
"""Fail on high-confidence committed secret material or private keys."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import pathlib
|
||||
import re
|
||||
import subprocess
|
||||
import sys
|
||||
|
||||
SKIP_PARTS = {".git", "node_modules", "dist", "bin", "artifacts"}
|
||||
PRIVATE_KEY = re.compile(r"-----BEGIN (?:RSA |EC |OPENSSH )?PRIVATE KEY-----")
|
||||
TOKEN_MARKERS = re.compile(r"(?:ghp_|github_pat_|sk-[A-Za-z0-9]{12,}|xox[baprs]-[A-Za-z0-9-]{12,})")
|
||||
|
||||
|
||||
def main() -> int:
|
||||
root = pathlib.Path(__file__).resolve().parents[1]
|
||||
files = subprocess.check_output(["git", "ls-files", "-z"], cwd=root).decode().split("\0")
|
||||
findings: list[str] = []
|
||||
for name in files:
|
||||
if not name:
|
||||
continue
|
||||
path = root / name
|
||||
if any(part in SKIP_PARTS for part in path.parts) or path.name in {".env.example", "check_secrets.py"} or path.name.endswith("_test.go"):
|
||||
continue
|
||||
try:
|
||||
content = path.read_text(encoding="utf-8")
|
||||
except (UnicodeDecodeError, OSError):
|
||||
continue
|
||||
if PRIVATE_KEY.search(content):
|
||||
findings.append(f"private key marker: {name}")
|
||||
if TOKEN_MARKERS.search(content):
|
||||
findings.append(f"token marker: {name}")
|
||||
if findings:
|
||||
print("SECRET CHECK: FAIL")
|
||||
print("\n".join(findings))
|
||||
return 1
|
||||
print("SECRET CHECK: PASS")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Reference in New Issue
Block a user