Files
trufflehog/pkg/verificationcache/metrics_reporter.go
Cody Rose ddc015e5ed
Lint / golangci-lint (push) Waiting to run
Lint / semgrep (push) Waiting to run
Release / Release (push) Waiting to run
Scan for secrets / test (push) Waiting to run
Test / test (push) Waiting to run
Test / test-community (push) Waiting to run
Implement verification cache (#3801)
This PR introduces a cache that allows the scanner to avoid emitting multiple requests to verify the same credential. In practice, it doesn't seem to reduce scan time at all, but it does seem to reduce the number of calls to FromData rather drastically.

The cache is implemented as an opt-out feature that can be disabled with a new CLI flag. If we don't like this, we can change it.

The metrics collection hopefully isn't too architecture-astronauty; I wanted to create something useful here that could also accommodate future Prometheus configuration without making the implementation all stupid.
2024-12-20 13:40:29 -08:00

29 lines
1.5 KiB
Go

package verificationcache
import "time"
// MetricsReporter is an interface used by a verification cache to report various metrics related to its operation.
// Implementations must be thread-safe.
type MetricsReporter interface {
// AddCredentialVerificationsSaved records "saved" verification attempts, which is when credential verification
// status is loaded from the cache instead of retrieved from a remote verification endpoint. This number might be
// smaller than the cache hit count due to cache hit "wasting"; see AddResultCacheHitsWasted for more information.
AddCredentialVerificationsSaved(count int)
// AddFromDataVerifyTimeSpent records wall time spent in calls to detector.FromData with verify=true.
AddFromDataVerifyTimeSpent(wallTime time.Duration)
// AddResultCacheHits records result cache hits. Not all cache hits result in elided remote verification requests
// due to cache hit "wasting"; see AddResultCacheHitsWasted for more information.
AddResultCacheHits(count int)
// AddResultCacheMisses records result cache misses.
AddResultCacheMisses(count int)
// AddResultCacheHitsWasted records "wasted" result cache hits. A "wasted" result cache hit is a result cache hit
// that does not elide a remote verification request because there are other secret findings in the relevant chunk
// that are not cached. When this happens, the detector's FromData method must be called anyway, so the cache hit
// doesn't save any remote requests.
AddResultCacheHitsWasted(count int)
}