Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions docs/introduction/configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,7 @@ common:
max_artifact_size: 100Mb
confidence_filter: medium # low, medium, high, high-verified
hit_timeout: 120 # Seconds
webui: false # Serve a local authenticated findings UI during scans
```

`secrets_verification` replaces the deprecated `trufflehog_verification` key. The old key (and `PIPELEEK_COMMON_TRUFFLEHOG_VERIFICATION`) is still read, with a warning, when the new key is not set.
Expand Down
9 changes: 9 additions & 0 deletions internal/cmd/bitbucket/scan/scan.go
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ import (
"github.com/CompassSecurity/pipeleek/internal/cmd/flags"
pkgscan "github.com/CompassSecurity/pipeleek/pkg/bitbucket/scan"
"github.com/CompassSecurity/pipeleek/pkg/config"
"github.com/CompassSecurity/pipeleek/pkg/webui"
"github.com/rs/zerolog/log"
"github.com/spf13/cobra"
)
Expand Down Expand Up @@ -35,6 +36,7 @@ var flagBindings = map[string]string{
"max-artifact-size": "common.max_artifact_size",
"confidence": "common.confidence_filter",
"hit-timeout": "common.hit_timeout",
"webui": "common.webui",
}

func NewScanCmd() *cobra.Command {
Expand Down Expand Up @@ -87,6 +89,10 @@ func Scan(cmd *cobra.Command, args []string) {
options.SecretsVerification = config.GetBool("common.secrets_verification")
maxArtifactSize = config.GetString("common.max_artifact_size")
options.ConfidenceFilter = config.GetStringSlice("common.confidence_filter")
ui := webui.StartIfEnabled(config.GetBool("common.webui"))
if ui != nil {
defer ui.Close()
}

if options.AccessToken != "" && options.Email == "" {
log.Fatal().Msg("When using --token you must also provide --email (or bitbucket.email in config)")
Expand Down Expand Up @@ -129,4 +135,7 @@ func Scan(cmd *cobra.Command, args []string) {
if err := scanner.Scan(); err != nil {
log.Fatal().Err(err).Msg("Scan failed")
}
if ui != nil {
ui.Wait()
}
}
9 changes: 9 additions & 0 deletions internal/cmd/circle/scan/scan.go
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ import (
circlescan "github.com/CompassSecurity/pipeleek/pkg/circle/scan"
"github.com/CompassSecurity/pipeleek/pkg/config"
"github.com/CompassSecurity/pipeleek/pkg/logging"
"github.com/CompassSecurity/pipeleek/pkg/webui"
"github.com/rs/zerolog"
"github.com/rs/zerolog/log"
"github.com/spf13/cobra"
Expand Down Expand Up @@ -57,6 +58,7 @@ var flagBindings = map[string]string{
"max-artifact-size": "common.max_artifact_size",
"confidence": "common.confidence_filter",
"hit-timeout": "common.hit_timeout",
"webui": "common.webui",
}

func NewScanCmd() *cobra.Command {
Expand Down Expand Up @@ -124,6 +126,10 @@ func Scan(cmd *cobra.Command, args []string) {
options.SecretsVerification = config.GetBool("common.secrets_verification")
options.ConfidenceFilter = config.GetStringSlice("common.confidence_filter")
maxArtifactSize = config.GetString("common.max_artifact_size")
ui := webui.StartIfEnabled(config.GetBool("common.webui"))
if ui != nil {
defer ui.Close()
}
hitTimeoutRaw := config.GetString("common.hit_timeout")
hitTimeout, err := time.ParseDuration(hitTimeoutRaw)
if err != nil {
Expand Down Expand Up @@ -163,4 +169,7 @@ func Scan(cmd *cobra.Command, args []string) {
if err := scanner.Scan(); err != nil {
log.Fatal().Err(err).Msg("Scan failed")
}
if ui != nil {
ui.Wait()
}
}
9 changes: 9 additions & 0 deletions internal/cmd/devops/scan/scan.go
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ import (
"github.com/CompassSecurity/pipeleek/internal/cmd/flags"
"github.com/CompassSecurity/pipeleek/pkg/config"
pkgscan "github.com/CompassSecurity/pipeleek/pkg/devops/scan"
"github.com/CompassSecurity/pipeleek/pkg/webui"
"github.com/rs/zerolog/log"
"github.com/spf13/cobra"
)
Expand Down Expand Up @@ -39,6 +40,7 @@ var flagBindings = map[string]string{
"max-artifact-size": "common.max_artifact_size",
"confidence": "common.confidence_filter",
"hit-timeout": "common.hit_timeout",
"webui": "common.webui",
}

func NewScanCmd() *cobra.Command {
Expand Down Expand Up @@ -95,6 +97,10 @@ func Scan(cmd *cobra.Command, args []string) {
options.SecretsVerification = config.GetBool("common.secrets_verification")
maxArtifactSize = config.GetString("common.max_artifact_size")
options.ConfidenceFilter = config.GetStringSlice("common.confidence_filter")
ui := webui.StartIfEnabled(config.GetBool("common.webui"))
if ui != nil {
defer ui.Close()
}

if err := config.ValidateURL(options.DevOpsURL, "Azure DevOps URL"); err != nil {
log.Fatal().Err(err).Msg("Invalid Azure DevOps URL")
Expand Down Expand Up @@ -128,4 +134,7 @@ func Scan(cmd *cobra.Command, args []string) {
if err := scanner.Scan(); err != nil {
log.Fatal().Err(err).Msg("Scan failed")
}
if ui != nil {
ui.Wait()
}
}
2 changes: 2 additions & 0 deletions internal/cmd/flags/common.go
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,8 @@ func addBaseScanFlags(cmd *cobra.Command, opts *config.CommonScanOptions) {
"Filter for confidence level, separate by comma if multiple. See readme for more info.")
cmd.Flags().DurationVarP(&opts.HitTimeout, "hit-timeout", "", 60*time.Second,
"Maximum time to wait for hit detection per scan item (e.g., 30s, 2m, 1h)")
cmd.Flags().BoolVarP(&opts.WebUI, "webui", "", false,
"Serve a local web UI for live findings on 127.0.0.1 with a random token")
Comment thread
frjcomp marked this conversation as resolved.
}

// AddCommonScanFlags adds the standard scanning flags that are common across all platforms.
Expand Down
9 changes: 9 additions & 0 deletions internal/cmd/gitea/scan/scan.go
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ import (
"github.com/CompassSecurity/pipeleek/internal/cmd/flags"
"github.com/CompassSecurity/pipeleek/pkg/config"
giteascan "github.com/CompassSecurity/pipeleek/pkg/gitea/scan"
"github.com/CompassSecurity/pipeleek/pkg/webui"
"github.com/rs/zerolog/log"
"github.com/spf13/cobra"
)
Expand Down Expand Up @@ -36,6 +37,7 @@ var flagBindings = map[string]string{
"max-artifact-size": "common.max_artifact_size",
"confidence": "common.confidence_filter",
"hit-timeout": "common.hit_timeout",
"webui": "common.webui",
}

var maxArtifactSize string
Expand Down Expand Up @@ -112,6 +114,10 @@ func Scan(cmd *cobra.Command, args []string) {
scanOptions.SecretsVerification = config.GetBool("common.secrets_verification")
maxArtifactSize = config.GetString("common.max_artifact_size")
scanOptions.ConfidenceFilter = config.GetStringSlice("common.confidence_filter")
ui := webui.StartIfEnabled(config.GetBool("common.webui"))
if ui != nil {
defer ui.Close()
}

if scanOptions.StartRunID > 0 && scanOptions.Repository == "" {
log.Fatal().Msg("--start-run-id can only be used with --repository flag")
Expand Down Expand Up @@ -157,4 +163,7 @@ func Scan(cmd *cobra.Command, args []string) {
if err := scanner.Scan(); err != nil {
log.Fatal().Err(err).Msg("Scan failed")
}
if ui != nil {
ui.Wait()
}
}
9 changes: 9 additions & 0 deletions internal/cmd/github/scan/scan.go
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ import (
"github.com/CompassSecurity/pipeleek/pkg/config"
pkgscan "github.com/CompassSecurity/pipeleek/pkg/github/scan"
"github.com/CompassSecurity/pipeleek/pkg/logging"
"github.com/CompassSecurity/pipeleek/pkg/webui"
"github.com/rs/zerolog"
"github.com/rs/zerolog/log"
"github.com/spf13/cobra"
Expand Down Expand Up @@ -44,6 +45,7 @@ var flagBindings = map[string]string{
"max-artifact-size": "common.max_artifact_size",
"confidence": "common.confidence_filter",
"hit-timeout": "common.hit_timeout",
"webui": "common.webui",
}

func NewScanCmd() *cobra.Command {
Expand Down Expand Up @@ -104,6 +106,10 @@ func Scan(cmd *cobra.Command, args []string) {
options.SecretsVerification = config.GetBool("common.secrets_verification")
maxArtifactSize = config.GetString("common.max_artifact_size")
options.ConfidenceFilter = config.GetStringSlice("common.confidence_filter")
ui := webui.StartIfEnabled(config.GetBool("common.webui"))
if ui != nil {
defer ui.Close()
}

if err := config.ValidateURL(options.GitHubURL, "GitHub URL"); err != nil {
log.Fatal().Err(err).Msg("Invalid GitHub URL")
Expand Down Expand Up @@ -142,4 +148,7 @@ func Scan(cmd *cobra.Command, args []string) {
if err := scanner.Scan(); err != nil {
log.Fatal().Err(err).Msg("Scan failed")
}
if ui != nil {
ui.Wait()
}
}
9 changes: 9 additions & 0 deletions internal/cmd/gitlab/cicd/scan/scan.go
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ import (
"github.com/CompassSecurity/pipeleek/pkg/gitlab/scan"
"github.com/CompassSecurity/pipeleek/pkg/logging"
"github.com/CompassSecurity/pipeleek/pkg/scanner/detectors"
"github.com/CompassSecurity/pipeleek/pkg/webui"
"github.com/rs/zerolog"
"github.com/rs/zerolog/log"
"github.com/spf13/cobra"
Expand Down Expand Up @@ -40,6 +41,7 @@ var flagBindings = map[string]string{
"secrets-verification": "common.secrets_verification",
"confidence": "common.confidence_filter",
"hit-timeout": "common.hit_timeout",
"webui": "common.webui",
}

func NewScanCmd() *cobra.Command {
Expand Down Expand Up @@ -103,8 +105,15 @@ func Scan(cmd *cobra.Command, args []string) {
HitTimeout: hitTimeout,
},
}
ui := webui.StartIfEnabled(config.GetBool("common.webui"))
if ui != nil {
defer ui.Close()
}

runScan(opts)
if ui != nil {
ui.Wait()
}
}

func runScan(opts scanOptions) {
Expand Down
9 changes: 9 additions & 0 deletions internal/cmd/gitlab/scan/scan.go
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ import (
"github.com/CompassSecurity/pipeleek/pkg/gitlab/scan"
"github.com/CompassSecurity/pipeleek/pkg/logging"
"github.com/CompassSecurity/pipeleek/pkg/scanner/detectors"
"github.com/CompassSecurity/pipeleek/pkg/webui"
"github.com/rs/zerolog"
"github.com/rs/zerolog/log"
"github.com/spf13/cobra"
Expand Down Expand Up @@ -45,6 +46,7 @@ var flagBindings = map[string]string{
"max-artifact-size": "common.max_artifact_size",
"confidence": "common.confidence_filter",
"hit-timeout": "common.hit_timeout",
"webui": "common.webui",
}

func NewScanCmd() *cobra.Command {
Expand Down Expand Up @@ -116,6 +118,10 @@ func Scan(cmd *cobra.Command, args []string) {
options.SecretsVerification = config.GetBool("common.secrets_verification")
maxArtifactSize = config.GetString("common.max_artifact_size")
options.ConfidenceFilter = config.GetStringSlice("common.confidence_filter")
ui := webui.StartIfEnabled(config.GetBool("common.webui"))
if ui != nil {
defer ui.Close()
}

if err := config.ValidateURL(gitlabUrl, "GitLab URL"); err != nil {
log.Fatal().Err(err).Msg("Invalid GitLab URL")
Expand Down Expand Up @@ -160,4 +166,7 @@ func Scan(cmd *cobra.Command, args []string) {
if err := scanner.Scan(); err != nil {
log.Fatal().Err(err).Msg("Scan failed")
}
if ui != nil {
ui.Wait()
}
}
9 changes: 9 additions & 0 deletions internal/cmd/gitlab/scanpublic/scan_public.go
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ import (
gitlabscan "github.com/CompassSecurity/pipeleek/pkg/gitlab/scan"
"github.com/CompassSecurity/pipeleek/pkg/logging"
"github.com/CompassSecurity/pipeleek/pkg/scanner/detectors"
"github.com/CompassSecurity/pipeleek/pkg/webui"
"github.com/rs/zerolog"
"github.com/rs/zerolog/log"
"github.com/spf13/cobra"
Expand Down Expand Up @@ -42,6 +43,7 @@ var flagBindings = map[string]string{
"max-artifact-size": "common.max_artifact_size",
"confidence": "common.confidence_filter",
"hit-timeout": "common.hit_timeout",
"webui": "common.webui",
}

func NewScanPublicCmd() *cobra.Command {
Expand Down Expand Up @@ -99,6 +101,10 @@ func ScanPublic(cmd *cobra.Command, args []string) {
secretsVerification := config.GetBool("common.secrets_verification")
maxArtifactSize = config.GetString("common.max_artifact_size")
confidenceFilter := config.GetStringSlice("common.confidence_filter")
ui := webui.StartIfEnabled(config.GetBool("common.webui"))
if ui != nil {
defer ui.Close()
}
hitTimeoutRaw := config.GetString("common.hit_timeout")
hitTimeout, err := time.ParseDuration(hitTimeoutRaw)
if err != nil {
Expand Down Expand Up @@ -145,4 +151,7 @@ func ScanPublic(cmd *cobra.Command, args []string) {
if err := scanner.Scan(); err != nil {
log.Fatal().Err(err).Msg("Public scan failed")
}
if ui != nil {
ui.Wait()
}
}
9 changes: 9 additions & 0 deletions internal/cmd/gitlab/snippets/scan/scan.go
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ import (
"github.com/CompassSecurity/pipeleek/pkg/config"
snippetscan "github.com/CompassSecurity/pipeleek/pkg/gitlab/snippets/scan"
"github.com/CompassSecurity/pipeleek/pkg/logging"
"github.com/CompassSecurity/pipeleek/pkg/webui"
"github.com/rs/zerolog"
"github.com/rs/zerolog/log"
"github.com/spf13/cobra"
Expand Down Expand Up @@ -37,6 +38,7 @@ var flagBindings = map[string]string{
"secrets-verification": "common.secrets_verification",
"confidence": "common.confidence_filter",
"hit-timeout": "common.hit_timeout",
"webui": "common.webui",
}

func NewScanCmd() *cobra.Command {
Expand Down Expand Up @@ -89,6 +91,10 @@ func Scan(cmd *cobra.Command, args []string) {
threads := config.GetInt("common.threads")
secretsVerification := config.GetBool("common.secrets_verification")
confidenceFilter := config.GetStringSlice("common.confidence_filter")
ui := webui.StartIfEnabled(config.GetBool("common.webui"))
if ui != nil {
defer ui.Close()
}
hitTimeoutRaw := config.GetString("common.hit_timeout")
hitTimeout, err := time.ParseDuration(hitTimeoutRaw)
if err != nil {
Expand Down Expand Up @@ -121,4 +127,7 @@ func Scan(cmd *cobra.Command, args []string) {
if err := scanner.Scan(); err != nil {
log.Fatal().Err(err).Msg("Snippets scan failed")
}
if ui != nil {
ui.Wait()
}
}
9 changes: 9 additions & 0 deletions internal/cmd/gitlab/tf/tf.go
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ import (
"github.com/CompassSecurity/pipeleek/internal/cmd/flags"
"github.com/CompassSecurity/pipeleek/pkg/config"
tfpkg "github.com/CompassSecurity/pipeleek/pkg/gitlab/tf"
"github.com/CompassSecurity/pipeleek/pkg/webui"
"github.com/rs/zerolog/log"
"github.com/spf13/cobra"
)
Expand All @@ -25,6 +26,7 @@ var flagBindings = map[string]string{
"secrets-verification": "common.secrets_verification",
"confidence": "common.confidence_filter",
"hit-timeout": "common.hit_timeout",
"webui": "common.webui",
}

func NewTFCmd() *cobra.Command {
Expand Down Expand Up @@ -74,6 +76,10 @@ func tfRun(cmd *cobra.Command, args []string) {
options.MaxScanGoRoutines = config.GetInt("common.threads")
options.ConfidenceFilter = config.GetStringSlice("common.confidence_filter")
options.SecretsVerification = config.GetBool("common.secrets_verification")
ui := webui.StartIfEnabled(config.GetBool("common.webui"))
if ui != nil {
defer ui.Close()
}
hitTimeoutRaw := config.GetString("common.hit_timeout")
hitTimeout, err := time.ParseDuration(hitTimeoutRaw)
if err != nil {
Expand All @@ -92,6 +98,9 @@ func tfRun(cmd *cobra.Command, args []string) {
}

tfpkg.ScanTerraformStates(tfOptions)
if ui != nil {
ui.Wait()
}

log.Info().Msg("Done, Bye Bye 🏳️‍🌈🔥")
}
Loading
Loading