diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml index 1300e88..c753664 100644 --- a/.github/workflows/secret-scan.yml +++ b/.github/workflows/secret-scan.yml @@ -6,18 +6,18 @@ jobs: runs-on: ubuntu-latest permissions: contents: "read" - outputs: - latest_release: ${{ steps.trufflehog_release.outputs.latest_release }} - latest_tag_name: ${{ steps.trufflehog_release.outputs.latest_tag_name }} steps: - name: Checkout Code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Install Cosign + id: cosign + continue-on-error: true # v4 of the action install v3 of the CLI. v4 of the CLI will deprecate some features so be aware. uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 - name: Pin Trufflehog to a known good release id: trufflehog_release - shell: bash + if: ${{ steps.cosign.outcome == 'success' }} + continue-on-error: true env: GH_TOKEN: ${{ github.token }} run: | @@ -35,7 +35,7 @@ jobs: done if [[ -z "$LATEST_TAG_NAME" ]]; then - echo "::error::No usable TruffleHog release found" + echo "::warning::No usable TruffleHog release found" exit 1 fi @@ -43,34 +43,60 @@ jobs: echo "latest_tag_name=$LATEST_TAG_NAME" >> "$GITHUB_OUTPUT" echo "latest_release=${LATEST_TAG_NAME#v}" >> "$GITHUB_OUTPUT" - name: Download and verify TruffleHog release + id: download + if: ${{ steps.trufflehog_release.outcome == 'success' }} + continue-on-error: true + env: + TRUFFLEHOG_TAG: ${{ steps.trufflehog_release.outputs.latest_tag_name }} + TRUFFLEHOG_VERSION: ${{ steps.trufflehog_release.outputs.latest_release }} run: | - curl -fsSL --retry 8 --retry-max-time 120 --retry-all-errors -w '%{url_effective} %{http_code}\n' -O https://github.com/trufflesecurity/trufflehog/releases/download/${{ steps.trufflehog_release.outputs.latest_tag_name }}/trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt - curl -fsSL --retry 8 --retry-max-time 120 --retry-all-errors -w '%{url_effective} %{http_code}\n' -O https://github.com/trufflesecurity/trufflehog/releases/download/${{ steps.trufflehog_release.outputs.latest_tag_name }}/trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt.pem - curl -fsSL --retry 8 --retry-max-time 120 --retry-all-errors -w '%{url_effective} %{http_code}\n' -O https://github.com/trufflesecurity/trufflehog/releases/download/${{ steps.trufflehog_release.outputs.latest_tag_name }}/trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt.sig - curl -fsSL --retry 8 --retry-max-time 120 --retry-all-errors -w '%{url_effective} %{http_code}\n' -O https://github.com/trufflesecurity/trufflehog/releases/download/${{ steps.trufflehog_release.outputs.latest_tag_name }}/trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_linux_amd64.tar.gz + base="https://github.com/trufflesecurity/trufflehog/releases/download/${TRUFFLEHOG_TAG}" + for file in \ + "trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt" \ + "trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt.pem" \ + "trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt.sig" \ + "trufflehog_${TRUFFLEHOG_VERSION}_linux_amd64.tar.gz" + do + curl -fsSL --retry 3 --retry-delay 5 --retry-all-errors \ + -w '%{url_effective} %{http_code}\n' -O "${base}/${file}" + done - cosign verify-blob trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt \ - --certificate trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt.pem \ - --signature trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt.sig \ + cosign verify-blob "trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt" \ + --certificate "trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt.pem" \ + --signature "trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt.sig" \ --certificate-identity-regexp 'https://github\.com/trufflesecurity/trufflehog/\.github/workflows/.+' \ --certificate-oidc-issuer "https://token.actions.githubusercontent.com" - sha256sum --ignore-missing -c trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt + sha256sum --ignore-missing -c "trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt" - name: Extract TruffleHog + id: extract + if: ${{ steps.download.outcome == 'success' }} + env: + TRUFFLEHOG_VERSION: ${{ steps.trufflehog_release.outputs.latest_release }} run: | - tar xzf trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_linux_amd64.tar.gz -C /usr/local/bin + tar xzf "trufflehog_${TRUFFLEHOG_VERSION}_linux_amd64.tar.gz" -C /usr/local/bin chmod +x /usr/local/bin/trufflehog - name: Run TruffleHog scan + if: ${{ steps.extract.outcome == 'success' }} continue-on-error: true id: scan run: | + args=(git file://. --only-verified --github-actions --fail --exclude-detectors="datadogtoken,lob") if [ -e .secret_scan_ignore ]; then - trufflehog git file://. --only-verified --github-actions --fail --exclude-paths=.secret_scan_ignore --exclude-detectors="datadogtoken,lob" - else - trufflehog git file://. --only-verified --github-actions --fail --exclude-detectors="datadogtoken,lob" + args+=(--exclude-paths=.secret_scan_ignore) fi + trufflehog "${args[@]}" + - name: Report scan skipped + if: ${{ !cancelled() && steps.scan.outcome == 'skipped' }} + env: + COSIGN_OUTCOME: ${{ steps.cosign.outcome }} + RELEASE_OUTCOME: ${{ steps.trufflehog_release.outcome }} + DOWNLOAD_OUTCOME: ${{ steps.download.outcome }} + EXTRACT_OUTCOME: ${{ steps.extract.outcome }} + run: | + echo "::warning::TruffleHog unavailable, this change was not scanned: cosign=$COSIGN_OUTCOME release=$RELEASE_OUTCOME download=$DOWNLOAD_OUTCOME extract=$EXTRACT_OUTCOME" - name: Send Alert to SIEM - id: alert + if: ${{ !cancelled() }} env: SIEM_WEBHOOK_URL: ${{ vars.SECRET_SCAN_SIEM_WEBHOOK_URL }} SCAN_OUTCOME: ${{ steps.scan.outcome }} @@ -94,9 +120,15 @@ jobs: pull_request="" fi + if [[ "$SCAN_OUTCOME" == "skipped" ]]; then + status="setup_failed" + else + status="$SCAN_OUTCOME" + fi + jq -n \ --arg event "github_secret_scanning" \ - --arg status "$SCAN_OUTCOME" \ + --arg status "$status" \ --arg createdAt "$created_at" \ --arg repo "$REPO" \ --arg pull_request "$pull_request" \ @@ -108,5 +140,5 @@ jobs: "$SIEM_WEBHOOK_URL" \ || echo "::warning::SIEM alert failed (non-blocking)" - name: Fail workflow if secret detected - if: ${{ !cancelled() && steps.scan.outcome != 'success' }} + if: ${{ !cancelled() && steps.scan.outcome == 'failure' }} run: exit 1