Lint / golangci-lint (push) Waiting to run
Lint / semgrep (push) Waiting to run
Release / Release (push) Waiting to run
Scan for secrets / test (push) Waiting to run
Test / test (push) Waiting to run
Test / test-community (push) Waiting to run
This PR introduces a cache that allows the scanner to avoid emitting multiple requests to verify the same credential. In practice, it doesn't seem to reduce scan time at all, but it does seem to reduce the number of calls to FromData rather drastically. The cache is implemented as an opt-out feature that can be disabled with a new CLI flag. If we don't like this, we can change it. The metrics collection hopefully isn't too architecture-astronauty; I wanted to create something useful here that could also accommodate future Prometheus configuration without making the implementation all stupid.
38 lines
1.0 KiB
Go
38 lines
1.0 KiB
Go
package verificationcache
|
|
|
|
import (
|
|
"sync/atomic"
|
|
"time"
|
|
)
|
|
|
|
// InMemoryMetrics is a MetricsReporter that stores reported metrics in memory for retrieval at the end of a scan.
|
|
type InMemoryMetrics struct {
|
|
CredentialVerificationsSaved atomic.Int32
|
|
FromDataVerifyTimeSpentMS atomic.Int64
|
|
ResultCacheHits atomic.Int32
|
|
ResultCacheHitsWasted atomic.Int32
|
|
ResultCacheMisses atomic.Int32
|
|
}
|
|
|
|
var _ MetricsReporter = (*InMemoryMetrics)(nil)
|
|
|
|
func (m *InMemoryMetrics) AddCredentialVerificationsSaved(count int) {
|
|
m.CredentialVerificationsSaved.Add(int32(count))
|
|
}
|
|
|
|
func (m *InMemoryMetrics) AddFromDataVerifyTimeSpent(wallTime time.Duration) {
|
|
m.FromDataVerifyTimeSpentMS.Add(wallTime.Milliseconds())
|
|
}
|
|
|
|
func (m *InMemoryMetrics) AddResultCacheHits(count int) {
|
|
m.ResultCacheHits.Add(int32(count))
|
|
}
|
|
|
|
func (m *InMemoryMetrics) AddResultCacheMisses(count int) {
|
|
m.ResultCacheMisses.Add(int32(count))
|
|
}
|
|
|
|
func (m *InMemoryMetrics) AddResultCacheHitsWasted(count int) {
|
|
m.ResultCacheHitsWasted.Add(int32(count))
|
|
}
|