Files
trufflehog/pkg/output/github_actions.go
Kashif Khan 74bb454e0d feat(output): add SARIF output format for GitHub code scanning (#5165)
Adds --sarif flag emitting a SARIF 2.1.0 log, buffered across the scan
and flushed once finished since SARIF isn't a streamable format like
the existing printers. Verified results map to "error", unverified to
"warning", with a stable per-finding fingerprint for cross-scan
new/fixed tracking when uploaded via github/codeql-action/upload-sarif.
2026-08-05 19:48:20 +05:00

74 lines
2.0 KiB
Go

package output
import (
"crypto/sha256"
"encoding/hex"
"fmt"
"sync"
"github.com/trufflesecurity/trufflehog/v3/pkg/context"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
)
var dedupeCache = make(map[string]struct{})
// GitHubActionsPrinter is a printer that prints results in GitHub Actions format.
type GitHubActionsPrinter struct{ mu sync.Mutex }
func (p *GitHubActionsPrinter) Print(_ context.Context, r *detectors.ResultWithMetadata) error {
out := gitHubActionsOutputFormat{
DetectorType: r.DetectorType.String(),
DetectorDescription: r.DetectorDescription,
DecoderType: r.DecoderType.String(),
Verified: r.Verified,
}
meta, err := structToMap(r.SourceMetadata.Data)
if err != nil {
return fmt.Errorf("could not marshal result: %w", err)
}
out.Filename, out.StartLine = extractFileAndLine(meta)
verifiedStatus := "unverified"
if out.Verified {
verifiedStatus = "verified"
}
key := fmt.Sprintf("%s:%s:%s:%s:%d", out.DecoderType, out.DetectorType, verifiedStatus, out.Filename, out.StartLine)
h := sha256.New()
h.Write([]byte(key))
key = hex.EncodeToString(h.Sum(nil))
p.mu.Lock()
defer p.mu.Unlock()
if _, ok := dedupeCache[key]; ok {
return nil
}
dedupeCache[key] = struct{}{}
name := ""
if nameValue, ok := r.ExtraData["name"]; ok {
name = fmt.Sprintf(" (%s)", nameValue)
}
message := fmt.Sprintf("Found %s %s%s result 🐷🔑\n", verifiedStatus, out.DetectorType, name)
if r.DecoderType != detectorspb.DecoderType_PLAIN {
message = fmt.Sprintf("Found %s %s%s result with %s encoding 🐷🔑\n", verifiedStatus, out.DetectorType, name, out.DecoderType)
}
fmt.Printf("::warning file=%s,line=%d,endLine=%d::%s",
out.Filename, out.StartLine, out.StartLine, message)
return nil
}
type gitHubActionsOutputFormat struct {
DetectorType string
DetectorDescription string
DecoderType string
Verified bool
StartLine int64
Filename string
}