UNPKG

@atomist/sdm-pack-aspect

Version:

an Atomist SDM Extension Pack for visualizing drift across an organization

71 lines 2.97 kB
"use strict"; /* * Copyright © 2019 Atomist, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. * You may obtain a copy of the License at * * http://www.apache.org/licenses/LICENSE-2.0 * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. * See the License for the specific language governing permissions and * limitations under the License. */ var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) { function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); } return new (P || (P = Promise))(function (resolve, reject) { function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } } function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } } function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); } step((generator = generator.apply(thisArg, _arguments || [])).next()); }); }; Object.defineProperty(exports, "__esModule", { value: true }); const automation_client_1 = require("@atomist/automation-client"); const _ = require("lodash"); /** * Sniff this project for exposed secrets. * Open every file. */ function sniffProject(project, options) { return __awaiter(this, void 0, void 0, function* () { let filesSniffed = 0; const startTime = new Date().getTime(); const exposedSecrets = _.flatten(yield automation_client_1.projectUtils.gatherFromFiles(project, options.globs, (f) => __awaiter(this, void 0, void 0, function* () { if (yield f.isBinary()) { return undefined; } ++filesSniffed; return sniffFileContent(project.id, f.path, yield f.getContent(), options); }))); return { options, filesSniffed, exposedSecrets, timeMillis: new Date().getTime() - startTime, }; }); } exports.sniffProject = sniffProject; function sniffFileContent(repoRef, path, content, opts) { return __awaiter(this, void 0, void 0, function* () { const exposedSecrets = []; for (const sd of opts.secretDefinitions) { const matches = content.match(sd.pattern) || []; matches .filter(m => !opts.whitelist.includes(m)) .forEach(m => exposedSecrets.push(({ repoRef, path, description: sd.description, secret: m, }))); } return exposedSecrets; }); } exports.sniffFileContent = sniffFileContent; //# sourceMappingURL=secretSniffing.js.map