Include merge diffs in git scanning

Merge commits can include novel changes not present in any parent, and
should be scanned.  The git log command with -p shows merge commits,
commits but without any diffs, so we were not scanning that content.

The "low memory" mode does get merge diffs in git show, but they're in a
format the parser isn't prepared to handle, and changes would need
careful testing.

There are a few ways to show the merge diffs, some make it easier to
show any novel changes, but require some parser/test adjustment or
version checks.  "first-parent" is the simplest "what did this merge
introduce" diff, meaning we double scan content from other parents, but
also include changes that are only in the merge.
This commit is contained in:
Meredith Howard
2026-09-10 12:29:52 -05:00
parent 4b7d1d3a68
commit 295d2f3760
2 changed files with 21 additions and 0 deletions
+2
View File
@@ -429,6 +429,8 @@ func (c *Parser) prepGitArgs(source string, head string, abbreviatedLog bool, ex
show: []string{
// https://git-scm.com/docs/git-show#Documentation/git-show.txt---patch
"--patch",
// https://git-scm.com/docs/git-log#Documentation/git-log.txt-first-parent
"--diff-merges=first-parent",
// https://git-scm.com/docs/git-log#Documentation/git-log.txt---dateformat
"--date=iso-strict",
// https://git-scm.com/docs/git-show#_pretty_formats
+19
View File
@@ -508,6 +508,8 @@ func TestSource_Chunks_Integration(t *testing.T) {
"8fe6f04ef1839e3fc54b5147e3d0e0b7ab971bd5-aws": {B: []byte("blah blaj\n\nthis is the secret: AKIA2E0A8F3B244C9986\n\nokay thank you bye\n"), Multi: true},
"84e9c75e388ae3e866e121087ea2dd45a71068f2-": {B: []byte("Dylan Ayrey <[email protected]>\nGitHub <[email protected]>\nUpdate aws\n")},
"84e9c75e388ae3e866e121087ea2dd45a71068f2-aws": {B: []byte("\n\nthis is the secret: [Default]\nAccess key Id: AKIAILE3JG6KMS3HZGCA\nSecret Access Key: 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\n\nokay thank you bye\n"), Multi: false},
"90c75f884c65dc3638ca1610bd9844e668f213c2-": {B: []byte("Dustin Decker <[email protected]>\nGitHub <[email protected]>\nMerge pull request #1 from dxa4481/patch-1\n\nUpdate aws\n")},
"90c75f884c65dc3638ca1610bd9844e668f213c2-aws": {B: []byte("\n\nthis is the secret: [Default]\nAccess key Id: AKIAILE3JG6KMS3HZGCA\nSecret Access Key: 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\n\nokay thank you bye\n"), Multi: false},
},
},
{
@@ -534,6 +536,23 @@ func TestSource_Chunks_Integration(t *testing.T) {
BaseHash: "master",
},
},
{
name: "remote repo, secret only present in merge",
repoURL: "https://github.com/mariduv/git-merge-leak.git",
expectedChunkData: map[string]*byteCompare{
"c68b1b9f952e5bd6e69aaaabea79ae28fcc0d53d-": {B: []byte("Meredith Howard <[email protected]>\nMeredith Howard <[email protected]>\nMerge branch 'some-branch'\n")},
"c68b1b9f952e5bd6e69aaaabea79ae28fcc0d53d-blah.txt": {B: []byte("\n\nWed Jul 15 10:00:58 CDT 2026\n")},
"c68b1b9f952e5bd6e69aaaabea79ae28fcc0d53d-blah2.txt": {B: []byte("Wed Jul 15 10:00:58 CDT 2026\n")},
"c68b1b9f952e5bd6e69aaaabea79ae28fcc0d53d-secret.aws": {B: []byte("[default]\naws_access_key_id = AKIAXYZDQCEN4B6JSJQI\naws_secret_access_key = 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\noutput = json\nregion = us-east-2\n")},
"be526890e9cbdf98233f2332c3617d13a26a8c32-": {B: []byte("Meredith Howard <[email protected]>\nMeredith Howard <[email protected]>\nUpdates\n")},
"be526890e9cbdf98233f2332c3617d13a26a8c32-blah.txt": {B: []byte("\nWed Jul 15 10:00:58 CDT 2026\n")},
"be526890e9cbdf98233f2332c3617d13a26a8c32-blah2.txt": {B: []byte("Wed Jul 15 10:00:58 CDT 2026\n")},
},
scanOptions: ScanOptions{
HeadHash: "c68b1b9f952e5bd6e69aaaabea79ae28fcc0d53d",
BaseHash: "c48635b82f3a203fee843cdc915abca1876e026b",
},
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {