Description: Add support for excluding paths in Docker source scanning: Add ExcludePaths field to Docker protobuf Implement path exclusion logic in docker.go Add comprehensive test coverage for exact and wildcard path matching Update engine to pass exclude paths configuration Add CLI support for --exclude-paths flag The implementation supports: Exact path matching (e.g., /var/log/test) Wildcard path matching (e.g., /var/log/test/*) Multiple exclude paths Tests ensure proper handling of: Exact path exclusions Wildcard exclusions Edge cases and similar paths References: https://github.com/trufflesecurity/trufflehog/issues/2216?utm_source=chatgpt.com
47 lines
1.5 KiB
Go
47 lines
1.5 KiB
Go
package engine
|
|
|
|
import (
|
|
"runtime"
|
|
|
|
"google.golang.org/protobuf/proto"
|
|
"google.golang.org/protobuf/types/known/anypb"
|
|
|
|
"github.com/trufflesecurity/trufflehog/v3/pkg/context"
|
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/sourcespb"
|
|
"github.com/trufflesecurity/trufflehog/v3/pkg/sources"
|
|
"github.com/trufflesecurity/trufflehog/v3/pkg/sources/docker"
|
|
)
|
|
|
|
// ScanDocker scans a given docker connection.
|
|
func (e *Engine) ScanDocker(ctx context.Context, c sources.DockerConfig) (sources.JobProgressRef, error) {
|
|
connection := &sourcespb.Docker{
|
|
Images: c.Images,
|
|
ExcludePaths: c.ExcludePaths,
|
|
}
|
|
|
|
switch {
|
|
case c.UseDockerKeychain:
|
|
connection.Credential = &sourcespb.Docker_DockerKeychain{DockerKeychain: true}
|
|
case len(c.BearerToken) > 0:
|
|
connection.Credential = &sourcespb.Docker_BearerToken{BearerToken: c.BearerToken}
|
|
default:
|
|
connection.Credential = &sourcespb.Docker_Unauthenticated{}
|
|
}
|
|
|
|
var conn anypb.Any
|
|
err := anypb.MarshalFrom(&conn, connection, proto.MarshalOptions{})
|
|
if err != nil {
|
|
ctx.Logger().Error(err, "failed to marshal gitlab connection")
|
|
return sources.JobProgressRef{}, err
|
|
}
|
|
|
|
sourceName := "trufflehog - docker"
|
|
sourceID, jobID, _ := e.sourceManager.GetIDs(ctx, sourceName, docker.SourceType)
|
|
|
|
dockerSource := &docker.Source{}
|
|
if err := dockerSource.Init(ctx, sourceName, jobID, sourceID, true, &conn, runtime.NumCPU()); err != nil {
|
|
return sources.JobProgressRef{}, err
|
|
}
|
|
return e.sourceManager.EnumerateAndScan(ctx, sourceName, dockerSource)
|
|
}
|