Files
trufflehog/hack/checksecretparts/README.md
Miccah ab5dd03ee0 Make detector Result.SecretParts initialization stricter (#4948)
* Update linter to disallow assigning SecretParts later

This means all detectors.Result objects must be created with the
SecretParts field set.

* Update documentation

* Migrate existing detectors to always initialize SecretParts
2026-05-05 08:30:41 -07:00

42 lines
1.4 KiB
Markdown

# checksecretparts
Static analysis check that finds detector packages which construct
`detectors.Result` values without populating the `SecretParts` field.
## What it checks
For each directory under `pkg/detectors/` (recursing into subpackages):
1. Find every composite literal of the form `detectors.Result{...}` or
`&detectors.Result{...}` in non-test `.go` files.
2. If the package does not mention `SecretParts` anywhere, emit a warning
for each construction site.
## Running locally
```sh
# Warning mode (default): prints findings, always exits 0 unless scanning fails.
go run ./hack/checksecretparts
# Scan specific directories instead of ./pkg/detectors.
go run ./hack/checksecretparts ./pkg/detectors/aws ./pkg/detectors/github
# Fail mode: exit 1 if any findings are reported. Use this once every detector
# has been migrated to populate SecretParts.
go run ./hack/checksecretparts -fail
```
## Flipping warning → fail
Once every detector populates `SecretParts`, make this check gating:
1. In `.github/workflows/lint.yml`, drop `continue-on-error: true` from the
`checksecretparts` job and change the run step to pass `-fail`.
2. Land any remaining migrations in the same PR as the flip.
## Scope limits
- It is a syntactic check. It matches `detectors.Result` by selector-expr
name; packages that rename the import (`d "...detectors"`) would not be
caught. No such rename exists in the current codebase.