* task: Datadog analyzer init commit with limited resources and permissions No cases covered * task: added more permissions * task: added more permissions | refactoring * task: added domain handling * refactor: incorporated PR feedback * task: Analyzer Result implementation for enterprise * task: added tests | Analysis Info configuration changes | permissions.yaml * revert: reverted datadog detector base URL * refactor: streamline Datadog API key analysis and permission handling - Simplified API key retrieval logic by removing redundant checks for "key". - Enhanced permission binding extraction by introducing a new function for permissions. - Cleaned up resource binding logic for better clarity and maintainability. - Removed unnecessary ID fields from scopes.json to reduce clutter.
Implementing Analyzers
Defining the Permissions
Permissions can be defined in:
- lower snake case as
permission_name:access_level - kebab case as
permission-name:read - dot notation as
permission.name:read
The Permissions are initially defined as a yaml file.
At the top of the analyzer implementation you specify the go generate command.
You can install the generator with go install github.com/trufflesecurity/trufflehog/v3/pkg/analyzer/generate_permissions.
Then you can run go generate ./... to generate the Permission types for the analyzer.
The generated Permission types are to be used in the AnalyzerResult struct when defining the Permissions and in your code.