Include merge diffs in git scanning
Merge commits can include novel changes not present in any parent, and should be scanned. The git log command with -p shows merge commits, commits but without any diffs, so we were not scanning that content. The "low memory" mode does get merge diffs in git show, but they're in a format the parser isn't prepared to handle, and changes would need careful testing. There are a few ways to show the merge diffs, some make it easier to show any novel changes, but require some parser/test adjustment or version checks. "first-parent" is the simplest "what did this merge introduce" diff, meaning we double scan content from other parents, but also include changes that are only in the merge.
This commit is contained in:
@@ -429,6 +429,8 @@ func (c *Parser) prepGitArgs(source string, head string, abbreviatedLog bool, ex
|
||||
show: []string{
|
||||
// https://git-scm.com/docs/git-show#Documentation/git-show.txt---patch
|
||||
"--patch",
|
||||
// https://git-scm.com/docs/git-log#Documentation/git-log.txt-first-parent
|
||||
"--diff-merges=first-parent",
|
||||
// https://git-scm.com/docs/git-log#Documentation/git-log.txt---dateformat
|
||||
"--date=iso-strict",
|
||||
// https://git-scm.com/docs/git-show#_pretty_formats
|
||||
|
||||
@@ -508,6 +508,8 @@ func TestSource_Chunks_Integration(t *testing.T) {
|
||||
"8fe6f04ef1839e3fc54b5147e3d0e0b7ab971bd5-aws": {B: []byte("blah blaj\n\nthis is the secret: AKIA2E0A8F3B244C9986\n\nokay thank you bye\n"), Multi: true},
|
||||
"84e9c75e388ae3e866e121087ea2dd45a71068f2-": {B: []byte("Dylan Ayrey <[email protected]>\nGitHub <[email protected]>\nUpdate aws\n")},
|
||||
"84e9c75e388ae3e866e121087ea2dd45a71068f2-aws": {B: []byte("\n\nthis is the secret: [Default]\nAccess key Id: AKIAILE3JG6KMS3HZGCA\nSecret Access Key: 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\n\nokay thank you bye\n"), Multi: false},
|
||||
"90c75f884c65dc3638ca1610bd9844e668f213c2-": {B: []byte("Dustin Decker <[email protected]>\nGitHub <[email protected]>\nMerge pull request #1 from dxa4481/patch-1\n\nUpdate aws\n")},
|
||||
"90c75f884c65dc3638ca1610bd9844e668f213c2-aws": {B: []byte("\n\nthis is the secret: [Default]\nAccess key Id: AKIAILE3JG6KMS3HZGCA\nSecret Access Key: 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\n\nokay thank you bye\n"), Multi: false},
|
||||
},
|
||||
},
|
||||
{
|
||||
@@ -534,6 +536,23 @@ func TestSource_Chunks_Integration(t *testing.T) {
|
||||
BaseHash: "master",
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "remote repo, secret only present in merge",
|
||||
repoURL: "https://github.com/mariduv/git-merge-leak.git",
|
||||
expectedChunkData: map[string]*byteCompare{
|
||||
"c68b1b9f952e5bd6e69aaaabea79ae28fcc0d53d-": {B: []byte("Meredith Howard <[email protected]>\nMeredith Howard <[email protected]>\nMerge branch 'some-branch'\n")},
|
||||
"c68b1b9f952e5bd6e69aaaabea79ae28fcc0d53d-blah.txt": {B: []byte("\n\nWed Jul 15 10:00:58 CDT 2026\n")},
|
||||
"c68b1b9f952e5bd6e69aaaabea79ae28fcc0d53d-blah2.txt": {B: []byte("Wed Jul 15 10:00:58 CDT 2026\n")},
|
||||
"c68b1b9f952e5bd6e69aaaabea79ae28fcc0d53d-secret.aws": {B: []byte("[default]\naws_access_key_id = AKIAXYZDQCEN4B6JSJQI\naws_secret_access_key = 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\noutput = json\nregion = us-east-2\n")},
|
||||
"be526890e9cbdf98233f2332c3617d13a26a8c32-": {B: []byte("Meredith Howard <[email protected]>\nMeredith Howard <[email protected]>\nUpdates\n")},
|
||||
"be526890e9cbdf98233f2332c3617d13a26a8c32-blah.txt": {B: []byte("\nWed Jul 15 10:00:58 CDT 2026\n")},
|
||||
"be526890e9cbdf98233f2332c3617d13a26a8c32-blah2.txt": {B: []byte("Wed Jul 15 10:00:58 CDT 2026\n")},
|
||||
},
|
||||
scanOptions: ScanOptions{
|
||||
HeadHash: "c68b1b9f952e5bd6e69aaaabea79ae28fcc0d53d",
|
||||
BaseHash: "c48635b82f3a203fee843cdc915abca1876e026b",
|
||||
},
|
||||
},
|
||||
}
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user