Richard Gomez 961f2e674f feat(generic-api-key): tune false positives (#1606) 1 gadu atpakaļ
..
1password.go 93acc6e82a feat(rules): add 1password token (#1583) 1 gadu atpakaļ
adafruit.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
adobe.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
age.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
airtable.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
algolia.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
alibaba.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
asana.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
atlassian.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
authress.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
aws.go 9152eaa57a feat(aws): add entropy & allowlist (#1582) 1 gadu atpakaļ
azure.go 8fb39ba8dc feat(azure): detect Azure AD client secrets (#1199) 1 gadu atpakaļ
beamer.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
bitbucket.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
bittrex.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
clojars.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
cloudflare.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
codecov.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
cohere.go 1a2f656278 feat: add cohere rule (#1549) 1 gadu atpakaļ
coinbase.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
config.tmpl 2db25f1367 feat(config): ignore swagger-ui assets (#1604) 1 gadu atpakaļ
confluent.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
contentful.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
curl.go 7206d6bc56 feat(curl): tweak tps and fps (#1603) 1 gadu atpakaļ
databricks.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
datadog.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
definednetworking.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
digitalocean.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
discord.go 8cfa6b2e43 fix(rules): add entropy (#1580) 1 gadu atpakaļ
doppler.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
droneci.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
dropbox.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
duffel.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
dynatrace.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
easypost.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
etsy.go 9e06824372 Restrict Etsy keywords (#1491) 1 gadu atpakaļ
facebook.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
fastly.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
finicity.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
finnhub.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
flickr.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
flutterwave.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
flyio.go 78f7d3f5df feat: create fly.io rule (#1528) 1 gadu atpakaļ
frameio.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
freshbooks.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
gcp.go df126a7473 feat(gcp): update api key rule (#1481) 1 gadu atpakaļ
generic.go 961f2e674f feat(generic-api-key): tune false positives (#1606) 1 gadu atpakaļ
github.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
gitlab.go 8cfa6b2e43 fix(rules): add entropy (#1580) 1 gadu atpakaļ
gitter.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
gocardless.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
grafana.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
harness.go e93a7c0d26 Update Harness rules to add _ and - in the account ID part. (#1503) 1 gadu atpakaļ
hashicorp.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
hashicorp_vault.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
heroku.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
hubspot.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
huggingface.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
infracost.go 8cfa6b2e43 fix(rules): add entropy (#1580) 1 gadu atpakaļ
intercom.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
intra42.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
jfrog.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
jwt.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
kraken.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
kubernetes.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
kucoin.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
launchdarkly.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
linear.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
linkedin.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
lob.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
mailchimp.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
mailgun.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
mapbox.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
mattermost.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
messagebird.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
netlify.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
newrelic.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
npm.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
nuget.go aabe381539 Define multiple allowlists per rule (#1496) 1 gadu atpakaļ
nytimes.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
okta.go 0afb525e59 feat(okta): bump entropy to 4 (#1599) 1 gadu atpakaļ
openai.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
openshift.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
plaid.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
planetscale.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
postman.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
prefect.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
privateai.go 00bb82153e feat: add PrivateAI rule (#1548) 1 gadu atpakaļ
privatekey.go bf8a49fc29 Make private key check less greedy and include fifth dash (#1440) 1 gadu atpakaļ
pulumi.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
pypi.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
rapidapi.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
readme.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
rubygems.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
scalingo.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
sendbird.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
sendgrid.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
sendinblue.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
sentry.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
shippo.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
shopify.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
sidekiq.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
slack.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
snyk.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
square.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
squarespace.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
stopwords.go e97695b852 feat(generic-api-key): exclude keywords (#1587) 1 gadu atpakaļ
stripe.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
sumologic.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
teams.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
telegram.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
travisci.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
trello.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
twilio.go 455ae0aab7 More rule fixes (#1586) 1 gadu atpakaļ
twitch.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
twitter.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
typeform.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
yandex.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ
zendesk.go bd81872eee Make config generation utils public (#1480) 1 gadu atpakaļ

readme.go

package rules

import (
"github.com/zricethezav/gitleaks/v8/cmd/generate/config/utils"
"github.com/zricethezav/gitleaks/v8/cmd/generate/secrets"
"github.com/zricethezav/gitleaks/v8/config"
)

func ReadMe() *config.Rule {
// define rule
r := config.Rule{
RuleID: "readme-api-token",
Description: "Detected a Readme API token, risking unauthorized documentation management and content exposure.",
Regex: utils.GenerateUniqueTokenRegex(`rdme_[a-z0-9]{70}`, false),
Entropy: 2,
Keywords: []string{
"rdme_",
},
}

// validate
tps := []string{
utils.GenerateSampleSecret("api-token", "rdme_"+secrets.NewSecret(utils.AlphaNumeric("70"))),
}
fps := []string{
`const API_KEY = 'rdme_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX';`,
}
return utils.Validate(r, tps, fps)
}