Clean up use of wasilibs/go-re2 (#5273)

* perf: switch nearly all remaining uses of stdlib regexp to wasilibs/go-re2
* perf: upgrade github.com/wasilibs/go-re2 from v1.9.0 to v1.12.0
* gofmt modified files
* snowflake detector: hoist constant regex compilation to package-level variables
* add golangci lint to steer folks to go-re2 instead of regexp
This commit is contained in:
Brad Larsen
2026-09-09 17:25:38 -04:00
committed by GitHub
parent e58aec687e
commit 2bffafb280
30 changed files with 71 additions and 59 deletions
+11
View File
@@ -0,0 +1,11 @@
version: "2"
linters:
enable:
- depguard
settings:
depguard:
rules:
no-stdlib-regexp:
deny:
- pkg: "regexp$"
desc: "use wasilibs/go-re2 unless necessary"
+3 -3
View File
@@ -98,7 +98,7 @@ require (
github.com/testcontainers/testcontainers-go/modules/postgres v0.42.1-0.20260423004847-9fc0246c3859
github.com/trufflesecurity/disk-buffer-reader v0.2.1
github.com/trufflesecurity/ldap-verify v0.0.0-20260824144701-aa52b4613a85
github.com/wasilibs/go-re2 v1.9.0
github.com/wasilibs/go-re2 v1.12.0
github.com/xo/dburl v0.23.8
gitlab.com/gitlab-org/api/client-go v1.12.0
go.mongodb.org/mongo-driver v1.17.7
@@ -284,14 +284,14 @@ require (
github.com/sorairolake/lzip-go v0.3.5 // indirect
github.com/spiffe/go-spiffe/v2 v2.6.0 // indirect
github.com/stretchr/objx v0.5.3 // indirect
github.com/tetratelabs/wazero v1.9.0 // indirect
github.com/tetratelabs/wazero v1.12.0 // indirect
github.com/therootcompany/xz v1.0.1 // indirect
github.com/tklauser/go-sysconf v0.4.0 // indirect
github.com/tklauser/numcpus v0.12.0 // indirect
github.com/trufflesecurity/touchfile v0.1.1 // indirect
github.com/ulikunitz/xz v0.5.15 // indirect
github.com/vbatts/tar-split v0.12.1 // indirect
github.com/wasilibs/wazero-helpers v0.0.0-20240620070341-3dff1577cd52 // indirect
github.com/wasilibs/wazero-helpers v0.0.0-20250123031827-cd30c44769bb // indirect
github.com/xanzy/ssh-agent v0.3.3 // indirect
github.com/xdg-go/pbkdf2 v1.0.0 // indirect
github.com/xdg-go/scram v1.1.2 // indirect
+6 -6
View File
@@ -724,8 +724,8 @@ github.com/testcontainers/testcontainers-go/modules/mysql v0.42.0 h1:Yhv1k7vDpyz
github.com/testcontainers/testcontainers-go/modules/mysql v0.42.0/go.mod h1:Z7SCTuiZlghAdRjkv3Ir0iXJKC2T2avbtxLR0DRe+ng=
github.com/testcontainers/testcontainers-go/modules/postgres v0.42.1-0.20260423004847-9fc0246c3859 h1:FQ0GtddzRvW5JpBtYSlhHuZDuIJ8ftjfeZfVDcqdCmU=
github.com/testcontainers/testcontainers-go/modules/postgres v0.42.1-0.20260423004847-9fc0246c3859/go.mod h1:wbXmKjW6MkKFaRP6YWwVR9ZDeq1tReh0wdWeutuDv+o=
github.com/tetratelabs/wazero v1.9.0 h1:IcZ56OuxrtaEz8UYNRHBrUa9bYeX9oVY93KspZZBf/I=
github.com/tetratelabs/wazero v1.9.0/go.mod h1:TSbcXCfFP0L2FGkRPxHphadXPjo1T6W+CseNNY7EkjM=
github.com/tetratelabs/wazero v1.12.0 h1:DuWcpNu/FzgEXgGBDp8J1Spc+CWOvvtvVyjKlaZopYU=
github.com/tetratelabs/wazero v1.12.0/go.mod h1:LvKtzl2RqO4gyF27BiXU+nKAjcV8f38U+kP/q2vgxh0=
github.com/therootcompany/xz v1.0.1 h1:CmOtsn1CbtmyYiusbfmhmkpAAETj0wBIH6kCYaX+xzw=
github.com/therootcompany/xz v1.0.1/go.mod h1:3K3UH1yCKgBneZYhuQUvJ9HPD19UEXEI0BWbMn8qNMY=
github.com/tklauser/go-sysconf v0.4.0 h1:7H0uAN+7RkwWRaxhYXDLqa5V3LPrJeV8wmD9dRUgPQU=
@@ -747,10 +747,10 @@ github.com/valyala/fastjson v1.6.4 h1:uAUNq9Z6ymTgGhcm0UynUAB6tlbakBrz6CQFax3BXV
github.com/valyala/fastjson v1.6.4/go.mod h1:CLCAqky6SMuOcxStkYQvblddUtoRxhYMGLrsQns1aXY=
github.com/vbatts/tar-split v0.12.1 h1:CqKoORW7BUWBe7UL/iqTVvkTBOF8UvOMKOIZykxnnbo=
github.com/vbatts/tar-split v0.12.1/go.mod h1:eF6B6i6ftWQcDqEn3/iGFRFRo8cBIMSJVOpnNdfTMFA=
github.com/wasilibs/go-re2 v1.9.0 h1:kjAd8qbNvV4Ve2Uf+zrpTCrDHtqH4dlsRXktywo73JQ=
github.com/wasilibs/go-re2 v1.9.0/go.mod h1:0sRtscWgpUdNA137bmr1IUgrRX0Su4dcn9AEe61y+yI=
github.com/wasilibs/wazero-helpers v0.0.0-20240620070341-3dff1577cd52 h1:OvLBa8SqJnZ6P+mjlzc2K7PM22rRUPE1x32G9DTPrC4=
github.com/wasilibs/wazero-helpers v0.0.0-20240620070341-3dff1577cd52/go.mod h1:jMeV4Vpbi8osrE/pKUxRZkVaA0EX7NZN0A9/oRzgpgY=
github.com/wasilibs/go-re2 v1.12.0 h1:sq3A6ZOqT90HYY25MD5/cG8Xv6uT2AhmPgBfkCfhp10=
github.com/wasilibs/go-re2 v1.12.0/go.mod h1:2W+7GrrdO4NHv7ITHz8Yy3a1IxzjZCk8JR5zgTprxZs=
github.com/wasilibs/wazero-helpers v0.0.0-20250123031827-cd30c44769bb h1:gQ+ZV4wJke/EBKYciZ2MshEouEHFuinB85dY3f5s1q8=
github.com/wasilibs/wazero-helpers v0.0.0-20250123031827-cd30c44769bb/go.mod h1:jMeV4Vpbi8osrE/pKUxRZkVaA0EX7NZN0A9/oRzgpgY=
github.com/xanzy/ssh-agent v0.3.3 h1:+/15pJfg/RsTxqYcX6fHqOXZwwMP+2VyYWJeWM2qQFM=
github.com/xanzy/ssh-agent v0.3.3/go.mod h1:6dzNDKs0J9rVPHPhaGCukekBHKqfl+L3KghI1Bc68Uw=
github.com/xdg-go/pbkdf2 v1.0.0 h1:Su7DPu48wXMwC3bs7MCNG+z4FhcyEuz5dlvchbq0B0c=
+1 -1
View File
@@ -7,10 +7,10 @@ import (
"encoding/json"
"errors"
"fmt"
regexp "github.com/wasilibs/go-re2"
"io"
"net/http"
"os"
"regexp"
"strings"
"github.com/fatih/color"
+1 -1
View File
@@ -6,8 +6,8 @@ import (
"database/sql"
"errors"
"fmt"
regexp "github.com/wasilibs/go-re2"
"os"
"regexp"
"strings"
"github.com/fatih/color"
@@ -5,8 +5,8 @@ package privatekey
import (
"errors"
"fmt"
regexp "github.com/wasilibs/go-re2"
"os"
"regexp"
"strings"
"sync"
"time"
@@ -2,9 +2,9 @@ package main
import (
"fmt"
regexp "github.com/wasilibs/go-re2"
"log"
"os"
"regexp"
"strings"
"text/template"
+1 -1
View File
@@ -2,10 +2,10 @@ package cleantemp
import (
"fmt"
regexp "github.com/wasilibs/go-re2"
"io"
"os"
"path/filepath"
"regexp"
"strconv"
"strings"
+4 -4
View File
@@ -3,8 +3,8 @@ package common
import (
"bufio"
"fmt"
regexp "github.com/wasilibs/go-re2"
"os"
"regexp"
"github.com/trufflesecurity/trufflehog/v3/pkg/context"
)
@@ -14,7 +14,7 @@ type Filter struct {
exclude *FilterRuleSet
}
type FilterRuleSet []regexp.Regexp
type FilterRuleSet []*regexp.Regexp
// FilterEmpty returns a Filter that always passes.
func FilterEmpty() *Filter {
@@ -39,7 +39,7 @@ func FilterFromFiles(includeFilterPath, excludeFilterPath string) (*Filter, erro
// If no includeFilterPath is provided, every pattern should pass the include rules.
if includeFilterPath == "" {
includeRules = &FilterRuleSet{*regexp.MustCompile("")}
includeRules = &FilterRuleSet{regexp.MustCompile("")}
}
filter := &Filter{
@@ -87,7 +87,7 @@ func FilterRulesFromFile(source string) (*FilterRuleSet, error) {
if err != nil {
return nil, fmt.Errorf("can not compile regular expression: %s", line)
}
rules = append(rules, *pattern)
rules = append(rules, pattern)
}
return &rules, nil
}
+13 -13
View File
@@ -1,8 +1,8 @@
package common
import (
regexp "github.com/wasilibs/go-re2"
"os"
"regexp"
"testing"
)
@@ -15,54 +15,54 @@ func TestFilterBasic(t *testing.T) {
tests := map[string]filterTest{
"IncludePassed": {
filter: Filter{
include: &FilterRuleSet{*regexp.MustCompile("test")},
include: &FilterRuleSet{regexp.MustCompile("test")},
},
pattern: "teststring",
pass: true,
},
"IncludeFiltered": {
filter: Filter{
include: &FilterRuleSet{*regexp.MustCompile("nomatch")},
include: &FilterRuleSet{regexp.MustCompile("nomatch")},
},
pattern: "teststring",
pass: false,
},
"ExcludePassed": {
filter: Filter{
include: &FilterRuleSet{*regexp.MustCompile("")},
exclude: &FilterRuleSet{*regexp.MustCompile("nomatch")},
include: &FilterRuleSet{regexp.MustCompile("")},
exclude: &FilterRuleSet{regexp.MustCompile("nomatch")},
},
pattern: "teststring",
pass: true,
},
"ExcludeFiltered": {
filter: Filter{
include: &FilterRuleSet{*regexp.MustCompile("")},
exclude: &FilterRuleSet{*regexp.MustCompile("test")},
include: &FilterRuleSet{regexp.MustCompile("")},
exclude: &FilterRuleSet{regexp.MustCompile("test")},
},
pattern: "teststring",
pass: false,
},
"IncludeExcludeDifferentPass": {
filter: Filter{
include: &FilterRuleSet{*regexp.MustCompile("test")},
exclude: &FilterRuleSet{*regexp.MustCompile("nomatch")},
include: &FilterRuleSet{regexp.MustCompile("test")},
exclude: &FilterRuleSet{regexp.MustCompile("nomatch")},
},
pattern: "teststring",
pass: true,
},
"IncludeExcludeDifferentFiltered": {
filter: Filter{
include: &FilterRuleSet{*regexp.MustCompile("nomatch")},
exclude: &FilterRuleSet{*regexp.MustCompile("test")},
include: &FilterRuleSet{regexp.MustCompile("nomatch")},
exclude: &FilterRuleSet{regexp.MustCompile("test")},
},
pattern: "teststring",
pass: false,
},
"IncludeExcludeSameFiltered": {
filter: Filter{
include: &FilterRuleSet{*regexp.MustCompile("test")},
exclude: &FilterRuleSet{*regexp.MustCompile("test")},
include: &FilterRuleSet{regexp.MustCompile("test")},
exclude: &FilterRuleSet{regexp.MustCompile("test")},
},
pattern: "teststring",
pass: false,
+1 -1
View File
@@ -2,7 +2,7 @@ package common
import (
"fmt"
"regexp"
regexp "github.com/wasilibs/go-re2"
"strconv"
"strings"
)
+2 -2
View File
@@ -1,7 +1,7 @@
package common
import (
"regexp"
regexp "github.com/wasilibs/go-re2"
"testing"
"github.com/stretchr/testify/assert"
@@ -95,7 +95,7 @@ func TestPasswordRegexCheck(t *testing.T) {
passwordRegexPat := PasswordRegexCheck(passwordPattern)
expectedRegexPattern := regexp.MustCompile(passwordRegex)
assert.Equal(t, passwordRegexPat.compiledRegex, expectedRegexPattern)
assert.Equal(t, expectedRegexPattern.String(), passwordRegexPat.compiledRegex.String())
testString := `password = "johnsmith123$!"
password='johnsmith123$!'
+1 -1
View File
@@ -8,7 +8,7 @@ import (
"io"
"maps"
"net/http"
"regexp"
"regexp" //nolint:depguard // used instead of github.com/wasilibs/go-re2 due to differences in utf-8 handling
"slices"
"strings"
+1 -1
View File
@@ -1,7 +1,7 @@
package custom_detectors
import (
"regexp"
regexp "github.com/wasilibs/go-re2"
"strconv"
"strings"
)
+1 -1
View File
@@ -2,7 +2,7 @@ package custom_detectors
import (
"fmt"
"regexp"
"regexp" //nolint:depguard // used instead of github.com/wasilibs/go-re2 due to differences in utf-8 handling
"strconv"
"strings"
)
+1 -1
View File
@@ -2,7 +2,7 @@ package decoders
import (
"bytes"
"regexp"
regexp "github.com/wasilibs/go-re2"
"strconv"
"unicode/utf8"
+1 -1
View File
@@ -2,8 +2,8 @@ package decoders
import (
"bytes"
regexp "github.com/wasilibs/go-re2"
"net/url"
"regexp"
"strings"
"golang.org/x/net/html"
@@ -7,10 +7,10 @@ import (
"encoding/base64"
"errors"
"fmt"
regexp "github.com/wasilibs/go-re2"
"io"
"net/http"
"net/url"
"regexp"
"strings"
"time"
@@ -3,8 +3,8 @@ package v2
import (
"context"
"errors"
regexp "github.com/wasilibs/go-re2"
"net/http"
"regexp"
"strings"
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
@@ -4,9 +4,9 @@ import (
"context"
"encoding/base64"
"fmt"
regexp "github.com/wasilibs/go-re2"
"io"
"net/http"
"regexp"
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
+5 -5
View File
@@ -5,7 +5,7 @@ import (
"database/sql"
"errors"
"fmt"
"regexp"
"regexp" //nolint:depguard // used instead of github.com/wasilibs/go-re2 due to differences in utf-8 handling
"strings"
"time"
@@ -16,12 +16,12 @@ import (
type Scanner struct {
detectors.DefaultMultiPartCredentialProvider
ignorePatterns []regexp.Regexp
ignorePatterns []*regexp.Regexp
}
func New(opts ...func(*Scanner)) *Scanner {
scanner := &Scanner{
ignorePatterns: []regexp.Regexp{},
ignorePatterns: []*regexp.Regexp{},
}
for _, opt := range opts {
opt(scanner)
@@ -32,13 +32,13 @@ func New(opts ...func(*Scanner)) *Scanner {
func WithIgnorePattern(ignoreStrings []string) func(*Scanner) {
return func(s *Scanner) {
var ignorePatterns []regexp.Regexp
var ignorePatterns []*regexp.Regexp
for _, ignoreString := range ignoreStrings {
ignorePattern, err := regexp.Compile(ignoreString)
if err != nil {
panic(fmt.Sprintf("%s is not a valid regex, error received: %v", ignoreString, err))
}
ignorePatterns = append(ignorePatterns, *ignorePattern)
ignorePatterns = append(ignorePatterns, ignorePattern)
}
s.ignorePatterns = ignorePatterns
+5 -4
View File
@@ -29,8 +29,11 @@ var (
// accountIdentifierPat matches Snowflake account identifiers in the format: XXXXXXX-XXXXX
// Example: ABC1234-EXAMPLE
accountIdentifierPat = regexp.MustCompile(detectors.PrefixRegex([]string{"account"}) + `\b([a-zA-Z]{7}-[0-9a-zA-Z-_]{1,255}(.privatelink)?)\b`)
// usernameExclusionPat defines characters that should not be present in usernames
usernameExclusionPat = `!@#$%^&*{}:<>,.;?()/\+=\s\n`
// exclude characters that should not be present in usernames
usernameRegexState = common.UsernameRegexCheck(`!@#$%^&*{}:<>,.;?()/\+=\s\n`)
passwordRegexState = common.PasswordRegexCheck(" \r\n") // Exclude spaces, carriage returns, and line feeds
)
const (
@@ -100,13 +103,11 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
return nil, nil
}
usernameRegexState := common.UsernameRegexCheck(usernameExclusionPat)
usernameMatches := usernameRegexState.Matches(data)
if len(usernameMatches) == 0 {
return nil, nil
}
passwordRegexState := common.PasswordRegexCheck(" \r\n") // Exclude spaces, carriage returns, and line feeds
passwordMatches := passwordRegexState.Matches(data)
if len(passwordMatches) == 0 {
return nil, nil
+1 -1
View File
@@ -1,9 +1,9 @@
package giturl
import (
regexp "github.com/wasilibs/go-re2"
"net/url"
"path/filepath"
"regexp"
"strconv"
"strings"
+1 -1
View File
@@ -6,9 +6,9 @@ import (
"encoding/xml"
"errors"
"fmt"
regexp "github.com/wasilibs/go-re2"
"io"
"path/filepath"
"regexp"
"strings"
"sync"
"time"
+1 -1
View File
@@ -1,9 +1,9 @@
package handlers
import (
regexp "github.com/wasilibs/go-re2"
"io"
"net/http"
"regexp"
"strings"
"testing"
+1 -1
View File
@@ -2,9 +2,9 @@ package handlers
import (
"context"
regexp "github.com/wasilibs/go-re2"
"io"
"net/http"
"regexp"
"strings"
"testing"
+1 -1
View File
@@ -2,8 +2,8 @@ package git
import (
"fmt"
regexp "github.com/wasilibs/go-re2"
"os/exec"
"regexp"
"strconv"
"strings"
+1 -1
View File
@@ -6,12 +6,12 @@ import (
"encoding/base64"
"errors"
"fmt"
regexp "github.com/wasilibs/go-re2"
"io"
"net/url"
"os"
"os/exec"
"path/filepath"
"regexp"
"runtime"
"strings"
"sync/atomic"
+1 -1
View File
@@ -2,7 +2,7 @@ package github_experimental
import (
"fmt"
"regexp"
regexp "github.com/wasilibs/go-re2"
"strings"
"sync"
+1 -1
View File
@@ -2,7 +2,7 @@ package postman
import (
"fmt"
"regexp"
regexp "github.com/wasilibs/go-re2"
"strings"
"github.com/trufflesecurity/trufflehog/v3/pkg/context"