protect.go 2.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105
  1. package cmd
  2. import (
  3. "os"
  4. "path/filepath"
  5. "time"
  6. "github.com/rs/zerolog/log"
  7. "github.com/spf13/cobra"
  8. "github.com/spf13/viper"
  9. "github.com/zricethezav/gitleaks/v8/config"
  10. "github.com/zricethezav/gitleaks/v8/detect"
  11. "github.com/zricethezav/gitleaks/v8/report"
  12. )
  13. func init() {
  14. protectCmd.Flags().Bool("staged", false, "detect secrets in a --staged state")
  15. rootCmd.AddCommand(protectCmd)
  16. }
  17. var protectCmd = &cobra.Command{
  18. Use: "protect",
  19. Short: "protect secrets in code",
  20. Run: runProtect,
  21. }
  22. func runProtect(cmd *cobra.Command, args []string) {
  23. initConfig()
  24. var vc config.ViperConfig
  25. if err := viper.Unmarshal(&vc); err != nil {
  26. log.Fatal().Err(err).Msg("Failed to load config")
  27. }
  28. cfg, err := vc.Translate()
  29. if err != nil {
  30. log.Fatal().Err(err).Msg("Failed to load config")
  31. }
  32. cfg.Path, _ = cmd.Flags().GetString("config")
  33. exitCode, _ := cmd.Flags().GetInt("exit-code")
  34. staged, _ := cmd.Flags().GetBool("staged")
  35. start := time.Now()
  36. // Setup detector
  37. detector := detect.NewDetector(cfg)
  38. detector.Config.Path, err = cmd.Flags().GetString("config")
  39. if err != nil {
  40. log.Fatal().Err(err)
  41. }
  42. source, err := cmd.Flags().GetString("source")
  43. if err != nil {
  44. log.Fatal().Err(err)
  45. }
  46. // if config path is not set, then use the {source}/.gitleaks.toml path.
  47. // note that there may not be a `{source}/.gitleaks.toml` file, this is ok.
  48. if detector.Config.Path == "" {
  49. detector.Config.Path = filepath.Join(source, ".gitleaks.toml")
  50. }
  51. // set verbose flag
  52. if detector.Verbose, err = cmd.Flags().GetBool("verbose"); err != nil {
  53. log.Fatal().Err(err)
  54. }
  55. // set redact flag
  56. if detector.Redact, err = cmd.Flags().GetBool("redact"); err != nil {
  57. log.Fatal().Err(err)
  58. }
  59. // get log options for git scan
  60. logOpts, err := cmd.Flags().GetString("log-opts")
  61. if err != nil {
  62. log.Fatal().Err(err)
  63. }
  64. // start git scan
  65. var findings []report.Finding
  66. if staged {
  67. findings, err = detector.DetectGit(source, logOpts, detect.ProtectStagedType)
  68. } else {
  69. findings, err = detector.DetectGit(source, logOpts, detect.ProtectType)
  70. }
  71. if err != nil {
  72. // don't exit on error, just log it
  73. log.Error().Err(err)
  74. }
  75. // log info about the scan
  76. log.Info().Msgf("scan completed in %s", time.Since(start))
  77. if len(findings) != 0 {
  78. log.Warn().Msgf("leaks found: %d", len(findings))
  79. } else {
  80. log.Info().Msg("no leaks found")
  81. }
  82. reportPath, _ := cmd.Flags().GetString("report-path")
  83. ext, _ := cmd.Flags().GetString("report-format")
  84. if reportPath != "" {
  85. if err = report.Write(findings, cfg, ext, reportPath); err != nil {
  86. log.Fatal().Err(err)
  87. }
  88. }
  89. if len(findings) != 0 {
  90. os.Exit(exitCode)
  91. }
  92. }