detect.go 3.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147
  1. package cmd
  2. import (
  3. "os"
  4. "path/filepath"
  5. "time"
  6. "github.com/rs/zerolog/log"
  7. "github.com/spf13/cobra"
  8. "github.com/spf13/viper"
  9. "github.com/zricethezav/gitleaks/v8/config"
  10. "github.com/zricethezav/gitleaks/v8/detect"
  11. "github.com/zricethezav/gitleaks/v8/report"
  12. )
  13. func init() {
  14. rootCmd.AddCommand(detectCmd)
  15. detectCmd.Flags().String("log-opts", "", "git log options")
  16. detectCmd.Flags().Bool("no-git", false, "treat git repo as a regular directory and scan those files, --log-opts has no effect on the scan when --no-git is set")
  17. }
  18. var detectCmd = &cobra.Command{
  19. Use: "detect",
  20. Short: "detect secrets in code",
  21. Run: runDetect,
  22. }
  23. func runDetect(cmd *cobra.Command, args []string) {
  24. initConfig()
  25. var (
  26. vc config.ViperConfig
  27. findings []report.Finding
  28. err error
  29. )
  30. // Load config
  31. if err = viper.Unmarshal(&vc); err != nil {
  32. log.Fatal().Err(err).Msg("Failed to load config")
  33. }
  34. cfg, err := vc.Translate()
  35. if err != nil {
  36. log.Fatal().Err(err).Msg("Failed to load config")
  37. }
  38. cfg.Path, _ = cmd.Flags().GetString("config")
  39. // start timer
  40. start := time.Now()
  41. // Setup detector
  42. detector := detect.NewDetector(cfg)
  43. detector.Config.Path, err = cmd.Flags().GetString("config")
  44. if err != nil {
  45. log.Fatal().Err(err)
  46. }
  47. source, err := cmd.Flags().GetString("source")
  48. if err != nil {
  49. log.Fatal().Err(err)
  50. }
  51. // if config path is not set, then use the {source}/.gitleaks.toml path.
  52. // note that there may not be a `{source}/.gitleaks.toml` file, this is ok.
  53. if detector.Config.Path == "" {
  54. detector.Config.Path = filepath.Join(source, ".gitleaks.toml")
  55. }
  56. // set verbose flag
  57. if detector.Verbose, err = cmd.Flags().GetBool("verbose"); err != nil {
  58. log.Fatal().Err(err)
  59. }
  60. // set redact flag
  61. if detector.Redact, err = cmd.Flags().GetBool("redact"); err != nil {
  62. log.Fatal().Err(err)
  63. }
  64. if fileExists(filepath.Join(source, ".gitleaksignore")) {
  65. detector.AddGitleaksIgnore(filepath.Join(source, ".gitleaksignore"))
  66. }
  67. // set exit code
  68. exitCode, err := cmd.Flags().GetInt("exit-code")
  69. if err != nil {
  70. log.Fatal().Err(err)
  71. }
  72. // determine what type of scan:
  73. // - git: scan the history of the repo
  74. // - no-git: scan files by treating the repo as a plain directory
  75. noGit, err := cmd.Flags().GetBool("no-git")
  76. if err != nil {
  77. log.Fatal().Err(err)
  78. }
  79. // start the detector scan
  80. if noGit {
  81. findings, err = detector.DetectFiles(source)
  82. if err != nil {
  83. // don't exit on error, just log it
  84. log.Error().Err(err)
  85. }
  86. } else {
  87. logOpts, err := cmd.Flags().GetString("log-opts")
  88. if err != nil {
  89. log.Fatal().Err(err)
  90. }
  91. findings, err = detector.DetectGit(source, logOpts, detect.DetectType)
  92. if err != nil {
  93. // don't exit on error, just log it
  94. log.Error().Err(err)
  95. }
  96. }
  97. // log info about the scan
  98. log.Info().Msgf("scan completed in %s", time.Since(start))
  99. if len(findings) != 0 {
  100. log.Warn().Msgf("leaks found: %d", len(findings))
  101. } else {
  102. log.Info().Msg("no leaks found")
  103. }
  104. // write report if desired
  105. reportPath, _ := cmd.Flags().GetString("report-path")
  106. ext, _ := cmd.Flags().GetString("report-format")
  107. if reportPath != "" {
  108. if err = report.Write(findings, cfg, ext, reportPath); err != nil {
  109. log.Fatal().Err(err)
  110. }
  111. }
  112. if len(findings) != 0 {
  113. os.Exit(exitCode)
  114. }
  115. }
  116. func fileExists(fileName string) bool {
  117. // check for a .gitleaksignore file
  118. info, err := os.Stat(fileName)
  119. if err != nil && !os.IsNotExist(err) {
  120. return false
  121. }
  122. if info != nil && err == nil {
  123. if !info.IsDir() {
  124. return true
  125. }
  126. }
  127. return false
  128. }