Files
Amaan Ullah bb506f63a1 Analyzer/datadog (#4132)
* task: Datadog analyzer init commit with limited resources and permissions
No cases covered

* task: added more permissions

* task: added more permissions | refactoring

* task: added domain handling

* refactor: incorporated PR feedback

* task: Analyzer Result implementation for enterprise

* task: added tests | Analysis Info configuration changes | permissions.yaml

* revert: reverted datadog detector base URL

* refactor: streamline Datadog API key analysis and permission handling

- Simplified API key retrieval logic by removing redundant checks for "key".
- Enhanced permission binding extraction by introducing a new function for permissions.
- Cleaned up resource binding logic for better clarity and maintainability.
- Removed unnecessary ID fields from scopes.json to reduce clutter.
2025-06-10 11:51:33 -05:00
..
2025-06-10 11:51:33 -05:00
2025-06-10 11:51:33 -05:00

Implementing Analyzers

Defining the Permissions

Permissions can be defined in:

  • lower snake case as permission_name:access_level
  • kebab case as permission-name:read
  • dot notation as permission.name:read

The Permissions are initially defined as a yaml file.

At the top of the analyzer implementation you specify the go generate command.

You can install the generator with go install github.com/trufflesecurity/trufflehog/v3/pkg/analyzer/generate_permissions.

Then you can run go generate ./... to generate the Permission types for the analyzer.

The generated Permission types are to be used in the AnalyzerResult struct when defining the Permissions and in your code.