4 ms·
We use this at GitHub to power the commit token scanning. It is very fast and handles multiple regexes at once. We are looking for secrets from multiple provide
by clarkbw 7y ago
We use this at GitHub to power the commit token scanning. It is very fast and handles multiple regexes at once. We are looking for secrets from multiple providers. Couldn’t find a better option for this type of usage.
- jakeogh 7y agoCan you elaborate? What providers?
- walls 7y agoFor example, if someone commits AWS keys to a GitHub repo, GitHub will alert AWS, AWS will revoke your keys and freeze the account until they're satisfied nothing is compromised. > https://github.blog/2018-10-17-behind-the-scenes-of-github-token-scanning/ https://github.blog/2018-10-17-behind-the-scenes-of-github-t...
- unixhero 7y agoWhat??? Even in a private repo?
- jakeogh 7y agothe blog says public repos... but good question. Is it only some people that can subscribe to high entropy strings? Github: I didnt opt-into 2FA: #439658 (3rd party auth required without 2FA)
- esnard 7y agoFrom the article: > Since April, we’ve worked with cloud service providers in private beta to scan all changes to public repositories and public Gists for credentials (GitHub doesn’t scan private code). Private repos are not scanned.
- clarkbw 7y agoPrivate repos aren't scanned and if we did offer the service to scan private repos we would only ever contact the repo owners and not the service providers. In the case of public repos we're in a race against time where bad actors are scraping the site and have automation created to use your tokens within seconds of a leak. Private repos scenarios are much simpler to deal with.
- klaas- 7y agoCan you run this as a pre-receive hook to actually prevent a public commit if it has suspicious patterns in it?
- pr0tocol_7 7y agoYou can use gitleaks to do this now. I added that feature in v3: https://github.com/zricethezav/gitleaks/releases/tag/v3.0.0 https://github.com/zricethezav/gitleaks/releases/tag/v3.0.0