Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
72 changes: 52 additions & 20 deletions .github/workflows/secret-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,18 +6,18 @@ jobs:
runs-on: ubuntu-latest
permissions:
contents: "read"
outputs:
latest_release: ${{ steps.trufflehog_release.outputs.latest_release }}
latest_tag_name: ${{ steps.trufflehog_release.outputs.latest_tag_name }}
steps:
- name: Checkout Code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install Cosign
id: cosign
continue-on-error: true
# v4 of the action install v3 of the CLI. v4 of the CLI will deprecate some features so be aware.
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
- name: Pin Trufflehog to a known good release
id: trufflehog_release
shell: bash
if: ${{ steps.cosign.outcome == 'success' }}
continue-on-error: true
env:
GH_TOKEN: ${{ github.token }}
run: |
Expand All @@ -35,42 +35,68 @@ jobs:
done

if [[ -z "$LATEST_TAG_NAME" ]]; then
echo "::error::No usable TruffleHog release found"
echo "::warning::No usable TruffleHog release found"
exit 1
fi

echo "Using TruffleHog version: $LATEST_TAG_NAME"
echo "latest_tag_name=$LATEST_TAG_NAME" >> "$GITHUB_OUTPUT"
echo "latest_release=${LATEST_TAG_NAME#v}" >> "$GITHUB_OUTPUT"
- name: Download and verify TruffleHog release
id: download
if: ${{ steps.trufflehog_release.outcome == 'success' }}
continue-on-error: true
env:
TRUFFLEHOG_TAG: ${{ steps.trufflehog_release.outputs.latest_tag_name }}
TRUFFLEHOG_VERSION: ${{ steps.trufflehog_release.outputs.latest_release }}
run: |
curl -fsSL --retry 8 --retry-max-time 120 --retry-all-errors -w '%{url_effective} %{http_code}\n' -O https://github.com/trufflesecurity/trufflehog/releases/download/${{ steps.trufflehog_release.outputs.latest_tag_name }}/trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt
curl -fsSL --retry 8 --retry-max-time 120 --retry-all-errors -w '%{url_effective} %{http_code}\n' -O https://github.com/trufflesecurity/trufflehog/releases/download/${{ steps.trufflehog_release.outputs.latest_tag_name }}/trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt.pem
curl -fsSL --retry 8 --retry-max-time 120 --retry-all-errors -w '%{url_effective} %{http_code}\n' -O https://github.com/trufflesecurity/trufflehog/releases/download/${{ steps.trufflehog_release.outputs.latest_tag_name }}/trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt.sig
curl -fsSL --retry 8 --retry-max-time 120 --retry-all-errors -w '%{url_effective} %{http_code}\n' -O https://github.com/trufflesecurity/trufflehog/releases/download/${{ steps.trufflehog_release.outputs.latest_tag_name }}/trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_linux_amd64.tar.gz
base="https://github.com/trufflesecurity/trufflehog/releases/download/${TRUFFLEHOG_TAG}"
for file in \
"trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt" \
"trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt.pem" \
"trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt.sig" \
"trufflehog_${TRUFFLEHOG_VERSION}_linux_amd64.tar.gz"
do
curl -fsSL --retry 3 --retry-delay 5 --retry-all-errors \
-w '%{url_effective} %{http_code}\n' -O "${base}/${file}"
done

cosign verify-blob trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt \
--certificate trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt.pem \
--signature trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt.sig \
cosign verify-blob "trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt" \
--certificate "trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt.pem" \
--signature "trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt.sig" \
--certificate-identity-regexp 'https://github\.com/trufflesecurity/trufflehog/\.github/workflows/.+' \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"

sha256sum --ignore-missing -c trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt
sha256sum --ignore-missing -c "trufflehog_${TRUFFLEHOG_VERSION}_checksums.txt"
- name: Extract TruffleHog
id: extract
if: ${{ steps.download.outcome == 'success' }}
env:
TRUFFLEHOG_VERSION: ${{ steps.trufflehog_release.outputs.latest_release }}
run: |
tar xzf trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_linux_amd64.tar.gz -C /usr/local/bin
tar xzf "trufflehog_${TRUFFLEHOG_VERSION}_linux_amd64.tar.gz" -C /usr/local/bin
chmod +x /usr/local/bin/trufflehog
Comment thread
sentry[bot] marked this conversation as resolved.
- name: Run TruffleHog scan
if: ${{ steps.extract.outcome == 'success' }}
continue-on-error: true
id: scan
run: |
args=(git file://. --only-verified --github-actions --fail --exclude-detectors="datadogtoken,lob")
if [ -e .secret_scan_ignore ]; then
trufflehog git file://. --only-verified --github-actions --fail --exclude-paths=.secret_scan_ignore --exclude-detectors="datadogtoken,lob"
else
trufflehog git file://. --only-verified --github-actions --fail --exclude-detectors="datadogtoken,lob"
args+=(--exclude-paths=.secret_scan_ignore)
fi
trufflehog "${args[@]}"
- name: Report scan skipped
if: ${{ !cancelled() && steps.scan.outcome == 'skipped' }}
env:
COSIGN_OUTCOME: ${{ steps.cosign.outcome }}
RELEASE_OUTCOME: ${{ steps.trufflehog_release.outcome }}
DOWNLOAD_OUTCOME: ${{ steps.download.outcome }}
EXTRACT_OUTCOME: ${{ steps.extract.outcome }}
run: |
echo "::warning::TruffleHog unavailable, this change was not scanned: cosign=$COSIGN_OUTCOME release=$RELEASE_OUTCOME download=$DOWNLOAD_OUTCOME extract=$EXTRACT_OUTCOME"
- name: Send Alert to SIEM
id: alert
if: ${{ !cancelled() }}
env:
SIEM_WEBHOOK_URL: ${{ vars.SECRET_SCAN_SIEM_WEBHOOK_URL }}
SCAN_OUTCOME: ${{ steps.scan.outcome }}
Expand All @@ -94,9 +120,15 @@ jobs:
pull_request=""
fi

Comment thread
Jeffreyhung marked this conversation as resolved.
if [[ "$SCAN_OUTCOME" == "skipped" ]]; then
status="setup_failed"
else
status="$SCAN_OUTCOME"
fi

jq -n \
--arg event "github_secret_scanning" \
--arg status "$SCAN_OUTCOME" \
--arg status "$status" \
Comment thread
cursor[bot] marked this conversation as resolved.
--arg createdAt "$created_at" \
--arg repo "$REPO" \
--arg pull_request "$pull_request" \
Expand All @@ -108,5 +140,5 @@ jobs:
"$SIEM_WEBHOOK_URL" \
|| echo "::warning::SIEM alert failed (non-blocking)"
- name: Fail workflow if secret detected
if: ${{ !cancelled() && steps.scan.outcome != 'success' }}
if: ${{ !cancelled() && steps.scan.outcome == 'failure' }}
run: exit 1
Loading