protect.go 3.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137
  1. package cmd
  2. import (
  3. "os"
  4. "path/filepath"
  5. "time"
  6. "github.com/rs/zerolog/log"
  7. "github.com/spf13/cobra"
  8. "github.com/spf13/viper"
  9. "github.com/zricethezav/gitleaks/v8/config"
  10. "github.com/zricethezav/gitleaks/v8/detect"
  11. "github.com/zricethezav/gitleaks/v8/report"
  12. )
  13. func init() {
  14. protectCmd.Flags().Bool("staged", false, "detect secrets in a --staged state")
  15. protectCmd.Flags().String("log-opts", "", "git log options")
  16. protectCmd.Flags().StringP("gitleaks-ignore-path", "i", ".", "path to .gitleaksignore file or folder containing one")
  17. rootCmd.AddCommand(protectCmd)
  18. }
  19. var protectCmd = &cobra.Command{
  20. Use: "protect",
  21. Short: "protect secrets in code",
  22. Run: runProtect,
  23. }
  24. func runProtect(cmd *cobra.Command, args []string) {
  25. initConfig()
  26. var vc config.ViperConfig
  27. if err := viper.Unmarshal(&vc); err != nil {
  28. log.Fatal().Err(err).Msg("Failed to load config")
  29. }
  30. cfg, err := vc.Translate()
  31. if err != nil {
  32. log.Fatal().Err(err).Msg("Failed to load config")
  33. }
  34. cfg.Path, _ = cmd.Flags().GetString("config")
  35. exitCode, _ := cmd.Flags().GetInt("exit-code")
  36. staged, _ := cmd.Flags().GetBool("staged")
  37. start := time.Now()
  38. // Setup detector
  39. detector := detect.NewDetector(cfg)
  40. detector.Config.Path, err = cmd.Flags().GetString("config")
  41. if err != nil {
  42. log.Fatal().Err(err).Msg("")
  43. }
  44. source, err := cmd.Flags().GetString("source")
  45. if err != nil {
  46. log.Fatal().Err(err).Msg("")
  47. }
  48. // if config path is not set, then use the {source}/.gitleaks.toml path.
  49. // note that there may not be a `{source}/.gitleaks.toml` file, this is ok.
  50. if detector.Config.Path == "" {
  51. detector.Config.Path = filepath.Join(source, ".gitleaks.toml")
  52. }
  53. // set verbose flag
  54. if detector.Verbose, err = cmd.Flags().GetBool("verbose"); err != nil {
  55. log.Fatal().Err(err).Msg("")
  56. }
  57. // set redact flag
  58. if detector.Redact, err = cmd.Flags().GetBool("redact"); err != nil {
  59. log.Fatal().Err(err).Msg("")
  60. }
  61. if detector.MaxTargetMegaBytes, err = cmd.Flags().GetInt("max-target-megabytes"); err != nil {
  62. log.Fatal().Err(err).Msg("")
  63. }
  64. // set color flag
  65. if detector.NoColor, err = cmd.Flags().GetBool("no-color"); err != nil {
  66. log.Fatal().Err(err).Msg("")
  67. }
  68. gitleaksIgnorePath, err := cmd.Flags().GetString("gitleaks-ignore-path")
  69. if err != nil {
  70. log.Fatal().Err(err).Msg("could not get .gitleaksignore path")
  71. }
  72. if fileExists(gitleaksIgnorePath) {
  73. if err = detector.AddGitleaksIgnore(gitleaksIgnorePath); err != nil {
  74. log.Fatal().Err(err).Msg("could not call AddGitleaksIgnore")
  75. }
  76. }
  77. if fileExists(filepath.Join(gitleaksIgnorePath, ".gitleaksignore")) {
  78. if err = detector.AddGitleaksIgnore(filepath.Join(gitleaksIgnorePath, ".gitleaksignore")); err != nil {
  79. log.Fatal().Err(err).Msg("could not call AddGitleaksIgnore")
  80. }
  81. }
  82. if fileExists(filepath.Join(source, ".gitleaksignore")) {
  83. if err = detector.AddGitleaksIgnore(filepath.Join(source, ".gitleaksignore")); err != nil {
  84. log.Fatal().Err(err).Msg("could not call AddGitleaksIgnore")
  85. }
  86. }
  87. // get log options for git scan
  88. logOpts, err := cmd.Flags().GetString("log-opts")
  89. if err != nil {
  90. log.Fatal().Err(err).Msg("")
  91. }
  92. // start git scan
  93. var findings []report.Finding
  94. if staged {
  95. findings, err = detector.DetectGit(source, logOpts, detect.ProtectStagedType)
  96. } else {
  97. findings, err = detector.DetectGit(source, logOpts, detect.ProtectType)
  98. }
  99. if err != nil {
  100. // don't exit on error, just log it
  101. log.Error().Err(err).Msg("")
  102. }
  103. // log info about the scan
  104. log.Info().Msgf("scan completed in %s", FormatDuration(time.Since(start)))
  105. if len(findings) != 0 {
  106. log.Warn().Msgf("leaks found: %d", len(findings))
  107. } else {
  108. log.Info().Msg("no leaks found")
  109. }
  110. reportPath, _ := cmd.Flags().GetString("report-path")
  111. ext, _ := cmd.Flags().GetString("report-format")
  112. if reportPath != "" {
  113. if err = report.Write(findings, cfg, ext, reportPath); err != nil {
  114. log.Fatal().Err(err).Msg("")
  115. }
  116. }
  117. if len(findings) != 0 {
  118. os.Exit(exitCode)
  119. }
  120. }