Commit Graph
4379 Commits
Author SHA1 Message Date
Mustansir Muzaffar 7b710fffbb some refactoring 2026-04-06 13:12:48 +05:00
Mustansir Muzaffar 7a3b8105dd change test_secret.png 2026-04-06 13:03:30 +05:00
Mustansir Muzaffar c1c5570dd4 support multiple ocr providers 2026-04-06 12:47:36 +05:00
Amaan Ullah 82c6657327 Merge branch 'main' into hackathon/ocr-handler 2026-04-04 23:07:19 +05:00
Dipto Chaudhuri bff3d2670b [CSM-1857] Fix expired Azure secrets being silently dropped (#4845)
* fix expired Azure secrets being silently dropped

The Azure Entra service principal v2 detector dropped findings entirely
when Azure returned AADSTS7000222 (secret expired). The `continue
SecretLoop` in ProcessData skipped result creation, causing expired
secrets to vanish from output and stop receiving last_seen updates.

Changed the ErrSecretExpired handler to emit an unverified result with
the expiry error preserved, consistent with how ErrSecretInvalid and
ErrConditionalAccessPolicy are handled.

Made-with: Cursor

* Address PR feedback: treat expired secret as definitively invalid

Reviewers noted that an expired secret (AADSTS7000222) is not an
indeterminate verification state — it is definitively invalid. Pass nil
instead of the verification error when creating the result, and update
tests accordingly.

Made-with: Cursor
2026-04-03 12:17:40 -04:00
Mustansir Muzaffar e54f4b428d use better model for accurate ocr 2026-04-03 21:05:20 +05:00
Aman Ullah 395ec12ad7 introduce OCR handler for supporting imgs and videos mime types 2026-04-03 18:14:06 +05:00
John Elliott b0ee281ec3 Add nil check and error context to GitHub analyzer (#4858)
Return an explicit error when AnalyzePermissions yields nil info
instead of passing nil to secretInfoToAnalyzerResult. Wrap classic
PAT repo/gist enumeration errors with context for easier debugging.
2026-04-02 15:56:49 -07:00
Hon a8770b879a Add AnalysisInfo to verified results (#4862)
* add analysis info to detectors

* coinbase?

* Revert "coinbase?"

This reverts commit 311212822b.

* only set if verified
2026-04-02 14:16:11 -07:00
Jordan Tunstill 239dc4e7fd handle AADSTS50173 as explicit revocation signal for azure refresh tokens (#4842)
* fix(azure-refresh-token): handle AADSTS50173 as explicit revocation signal

* added same functionality for ErrTokenExpired

* removed TokenLoop since it is no longer used

* removed the createResult to avoid guessing at the secret information.
2026-04-02 12:39:00 -07:00
Bryan Beverly e48f9039c8 Add release bot workflow for trufflehog releases (#4835)
Triggers on release publish events to run the release bot, which
generates release notes using GitHub, Jira, and AI services.

Adapted from the thog repo workflow with trufflehog-specific adjustments:
repository argument set to trufflehog, environment requirement removed
in favor of a repo-level secret, permissions restricted, and a fork
guard added for consistency with other trufflehog workflows.

Made-with: Cursor
2026-04-01 09:50:25 -07:00
Muneeb Ullah Khan 6bd2d14f7a Re-enabled TestAPKHandler test and updated artifact url (#4856) v3.94.2 2026-04-01 18:01:15 +05:00
Muneeb Ullah Khan 681b305b3c Updated google.golang.org/grpc v1.78.0 --> v1.79.3 (#4852) 2026-04-01 18:00:50 +05:00
Amaan Ullah e81c0fc099 Add Shopify OAuth Detector (#4738)
* add shopify oauth detector

* embed multipart credential provider

* fix shopifyoauth SSRF: use DetectorHttpClientWithNoLocalAddresses

* remove unnecessary Analysis info
2026-04-01 17:53:42 +05:00
Arun Kumar Rai 03acc788f8 todoist: replace deprecated verification endpoint (#4828) 2026-04-01 10:41:21 +05:00
Nabeel Alam bfaa370c78 updated detectors.proto and made protos (#4853) 2026-04-01 10:34:31 +05:00
Jeff Ober 6171fa9f66 fix: replace release-guard workflow with revert-latest job (#4838)
Also adds comments to:
- .goreleaser.yml: explains why make_release is set to false
- .github/workflows/release.yml: document release/artifact state at each step
2026-03-27 12:37:28 -06:00
Shahzad Haider 61d57c10a5 skipping TestAPKHandler because the apk file being used in this test is unavailable (#4841) 2026-03-27 12:24:48 +05:00
Amaan Ullah 586f66d788 use struct-based SourceMetadataFunc signature across git sources (#4813)
* use struct-based SourceMetadataFunc signature across git sources

* incorporated feedback

- pass SourceMetadataInfo by value
- remove LegacySourceMetadataFunc
v3.94.1
2026-03-24 16:22:30 +05:00
6c64db94d5 Expand tilde manually in TUI (#4827)
* Fix command injection vulnerability in TUI

The TUI was building a command string from user input via string
concatenation and passing it to `sh -c` through syscall.Exec. This
allowed shell metacharacters in any TUI input field (git URI, file
path, tokens, etc.) to be interpreted as shell commands.

Replace the `sh -c` invocation with a direct syscall.Exec of the
trufflehog binary, passing arguments as a proper argv array. This
eliminates shell interpretation entirely.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add tilde expansion for TUI args after removing shell layer

Since sh -c was removed to fix command injection, ~/foo paths entered
in the TUI are no longer expanded by a shell. This adds a narrow
expandTilde helper that replaces a leading ~ with os.UserHomeDir()
before exec, restoring path resolution without reintroducing any
shell interpretation.

Guards against empty $HOME to prevent ~/foo silently resolving to /foo.

Made-with: Cursor

---------

Co-authored-by: Bryan Beverly <bryan.beverly@trufflesec.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
v3.94.0
2026-03-20 07:39:48 -07:00
Charlie Gunyon afd5336caa Confine symlink state handling to scanSymlink in Filesystem source (#4807)
* Confine symlink state handling to scanSymlink in Filesystem source

* Fix s.canFollowSymlinks snafu

* Update symlink tests to use starting depth 0

* Missed one

* Remove symlink checking from scanFile; this is now always handled in scanSymlink

* Confine errgroup.Groups to scanDir in the Filesystem source (#4808)

* Move path parameter after rootPath parameter in the Filesystem source

* Move the depth parameter too

* Only create an errgroup.Group inside scanDir (where it's used) in the Filesystem source
2026-03-17 11:13:10 +01:00
Casey Tran d17df48451 Add test cases for escaped unicode (#4812)
The purpose of this PR is to add escaped unicode test cases for the engine tests.
2026-03-13 09:31:45 -05:00
Bryan BeverlyandCursor aeb12782f0 Update README formatting and CLI help output (#4758)
* Update README formatting and CLI help output

Simplify HTML markup to plain markdown, update the git --help output
to reflect current flags and subcommands, and fix minor formatting
inconsistencies.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Update README: remove $ prompts and refresh CLI help output

Remove leading $ from example commands and replace outdated
trufflehog git --help output with current CLI flags and subcommands.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-03-12 09:15:28 -07:00
Mustansir 42b02effea Add anypoint oauth2 detector to defaults.go (#4722)
* add anypoiny oauth2 to defaults.go, add analysisinfo

* add analysisinfo in the correct place
2026-03-12 17:32:26 +05:00
Muneeb Ullah Khan 4860052fc9 Analysis info now uses snake case (#4765)
* removed camel case and used snake_case for consistency with analyzer

* updated case in test
2026-03-11 16:06:44 +05:00
Muneeb Ullah Khan f9d1850dad [INS-241] Datadogapikey detector (#4627)
* [INS-241] New detector (datadogapikey) for datadog apikeys

* Analyzer updated to cater endpoint

* Added new tests for anlyzers

* Removed print statement

* resolved comments and fixed integration tests.

* resolved comments

* changed cli prompt

* Fixed the comments and added app key validation in analyzer

* renamed regex variable

* Added found verified endpoint to ExtraData

* Clean up Analyze function by removing comments

Removed commented-out code for appKey and endpoint.

* [INS-286] Added support to analyze just the apikey in datadog's analyzer

* fixed linter issue

* fixed comment and introduced snake case to make analyzer code cosistent and also fixed flaky tests

* resolved bugbot comment

* updated protos

* resolve conflicts

* updated protobuffs and resolved bugbot comments

* made regex idiomatic

* fixed ssrf vulnerability

* fixed string formatting
2026-03-11 16:04:51 +05:00
Muneeb Ullah Khan 16d6dcf000 [INS-254] Datadog detector verification fix and endpoint configuration (#4616)
* [INS-233] Added support to verify token agains all datadog domains

* [INS-233] Added support to verify token agains all datadog domains

* Fixed cloud endpoint test

* Added precedence to endpoint selection userdefiner -> datafound -> default

* fixed one integration test

* [INS-240] add API key verification fallback when app key verification fails

* Resolved comments

* Fixed the tests according to new changes

* Removed apikey verification logic datadogtoken file

* Reverted the engine test changed earlier

* Resolved comment(s)

* added /api to endpoint

* removed unecessary print

* removed configuredEndpoint to simplify logic

* removed matching with /api suffix

* Fixed the failing integration test

* Update keys in AnalysisInfo map to use snake_case

* fixed bot comments

* fixed ssrf vulnerablity
2026-03-11 15:51:35 +05:00
Charlie Gunyon bc31aa9770 Rearrange some method parameters in the Filesystem source (#4806)
* Move path parameter after rootPath parameter in the Filesystem source

* Move the depth parameter too
2026-03-11 11:21:47 +01:00
Charlie Gunyon 5fb6dfd56a Make naming more consistent in the Filesystem source (#4805)
* Make naming more consistent in the Filesystem source

* Missed one
2026-03-11 11:11:46 +01:00
Charlie Gunyon b2122e4eb2 Use trContext instead of context throughout Filesystem source (#4804) 2026-03-11 10:13:08 +01:00
Cody Rose 6c05c4a00b Stop growing filesystem resume data (#4797)
#4742 (4563dde124) introduced a change to the filesystem source resumption tracking that caused it to start growing linearly with subdirectory count - which causes the payload to get intractably big on large data sets. This commit is an attempt to resolve the issue.

Note that the resumption code still has a bug that can cause data to get inadvertently skipped due to mishandling of the internal parallelization of the scan. This bug has been present for a long time and is present in other sources, so fixing it is out of scope here.

This commit _also_ introduces a new bug related to the fact that lexicographic sorting is not completely appropriate for the resumption check. This needs to be cleaned up as a fast follow, but it's still less serious than the current bug that prevents all scans of large data sets.
v3.93.8
2026-03-09 16:02:57 -04:00
meredith ef63d66d58 fix: make LDAP verification context-aware (#4768)
I forked go-ldap/ldap from someone else's PR that had partial work to
add contexts, then added just enough to have context on Bind, which
could block if the server does the delay-on-bad-password thing, in
addition to the Dial itself timing out.

there's more room to improve LDAP verification but for now it can't
hold up scanning
2026-03-06 09:55:19 -06:00
Amaan Ullah c3e599b716 fix JDBC detector regex truncating trailing non-alphanumeric password characters (#4755) v3.93.7 2026-03-04 16:56:42 +01:00
Shahzad Haider 71c48afda8 Added detector for JFrog Artifactory Reference Tokens (#4684)
* added detector for artifactory reference tokens

* add artifactory reference token detector to the no cloud endpoints list

* address mustansir feedback; remove the invalid host deletion

* use detectors.DetectorHttpClientWithNoLocalAddresses instead of common.SaneHttpClient() just like sibling artifactory detector
2026-03-04 16:56:24 +01:00
Dustin DeckerandCursor Agent 648aca62d5 Thread original chunk data through engine pipeline (#4780)
* [secret-storage] Thread original chunk data through engine pipeline

Adds OriginalData/ChunkData fields to preserve pre-decode source data
through the scan pipeline:

1. Chunk.OriginalData: captures chunk.Data before iterativeDecode
2. engine.go: sets chunk.OriginalData = chunk.Data before decode
3. ResultWithMetadata.ChunkData: populated by CopyMetadata from
   OriginalData (falls back to Data when nil)

This enables downstream consumers (e.g. the dispatcher in thog) to
access the original source data for secret storage encryption.

* Update TestChunkSize for OriginalData field addition

Chunk struct grew from 80 to 104 bytes with the OriginalData []byte
slice header (24 bytes). Field placement is already optimal (adjacent
to Data []byte).

* fix: preserve OriginalData field in EscapedUnicode decoder

The EscapedUnicode decoder constructed a new sources.Chunk manually
copying fields but omitted OriginalData. This caused CopyMetadata to
fall back to the decoded Data instead of the original pre-decode content,
defeating the purpose of preserving original chunk data for secret
storage encryption.

* Address PR review feedback: use testify/assert, add nil-guard comment, remove stale alignment comment

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-03-03 14:34:05 -05:00
Muneeb Ullah Khan 8df943f829 [INS-331] Fix the issue causing the tests file system soruce tests to fail on windows (#4743)
* fix excludepaths flag causing the test to fail

* fixed bugbot comms
2026-03-03 15:13:41 +05:00
Cody Rose 041f07e9df Move verify flag into detectableChunk (#4558)
Chunk.Verify is an odd field - it originally conveys whether a source is going to run with verification, but then, at a certain point in the scanning pipeline, is mutated such that it instead indicates whether the chunk should be scanned with verification - which is not solely dependent on the source's verify flag. This is unnecessarily difficult to understand and maintain. This commit separates those two pieces of information into two flags:

- Chunk.Verify has been renamed to Chunk.SourceVerify
- It is no longer mutated; instead "should this chunk's secrets be verified?" is now captured by a new field on detectableChunk
v3.93.6
2026-02-27 10:05:52 -05:00
Bill Rich e976603057 GH_TOKEN needed for gh (#4772) 2026-02-26 12:28:26 -08:00
Bill Rich 7cdc7ef878 Fix race condition in release process (#4766)
* Close window between release and artifact creation

* Use alternate method of falling back

* Remove unused env vars
v3.93.5
2026-02-26 11:28:23 -08:00
Brad Larsen 4f1d07f7c3 Fix typos in comments in json-enumerator source (#4764) 2026-02-24 10:41:20 -05:00
Muneeb Ullah Khan 4563dde124 [INS-283] Support following symlinks in filesystem source (#4742)
* enabled symlinks with maximum depth support

* resolved concurrency bugs and added maxDepthOption to cli

* Removed visited path map and tracked symlink depth by maintaining a counter variable

* separated symlink scanning from scanDir

* resolved bugbot comments

* introduced hash as a separator to avoid collisions
2026-02-24 20:10:16 +05:00
be889fa341 added rotation on 403s access_refused, this detector considered them indeterminate failures (#4740)
* added rotation on 403s, it appears that this detector considered them to be indeterminate failures

* tightened logic for rotation

* Apply suggestion from @nabeelalam

Co-authored-by: Nabeel Alam <nabeelalam811@gmail.com>

* Modify error return for RabbitMQ access refusal

Update error handling to return nil instead of the error for specific access issues.

---------

Co-authored-by: Kashif Khan <70996046+kashifkhan0771@users.noreply.github.com>
Co-authored-by: Nabeel Alam <nabeelalam811@gmail.com>
2026-02-23 15:02:59 -08:00
e3cbb3afc6 fix(ftp): set read deadline on connection to prevent indefinite hang (#4759)
* fix(ftp): set read deadline on connection to prevent indefinite hang

The FTP detector uses ftp.DialWithTimeout to bound the TCP connection,
but after the connection is established the banner read and login have
no deadline. If a server accepts TCP but never sends a response, the
detector blocks indefinitely, stalling the entire scan pipeline.

Switch to DialWithDialFunc and set a deadline on the connection that
covers the full handshake (banner + login).

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ftp): check error return from conn.SetDeadline

Co-authored-by: Dylan Ayrey <dxa4481@rit.edu>

---------

Co-authored-by: Dylan Ayrey <dylan@Dylans-MacBook-Pro.local>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Dylan Ayrey <dxa4481@rit.edu>
2026-02-23 08:25:57 -08:00
Muneeb Ullah KhanandKashif Khan 0de585530c [INS-309]updated google api version to v0.259.0 (#4736)
* updated google api version to v0.259.0

* fixed panic in test

---------

Co-authored-by: Kashif Khan <70996046+kashifkhan0771@users.noreply.github.com>
2026-02-23 19:57:57 +05:00
Miccah ec1d9a6b4b Refactor log package (#4734)
* Replace logConfig with zapcore.Core

* Add SyncFunc type and tests

* Change Sentry functions to accept a *sentry.Client

This allows the caller to do the error handling.

* Rename newCoreConfig to newCore

* Remove redundant WithCore option

* Update doc comments
2026-02-20 11:03:16 -08:00
Mustansir 7c84b27f62 [INS-246] Add Google Gemini API key detector (#4649)
* add google gemini api key detector

* change detector name to google cloud api key, mark as verified if 403 is returned

* add build tags for integration test

* changes in defaults.go

* Revert "changes in defaults.go"

This reverts commit 12e7b6f4aa.

* Revert "change detector name to google cloud api key, mark as verified if 403 is returned"

This reverts commit e46bb29b40.

* revert google cloud api changes, change keyword to gemini, add extra field active_google_key

* use aizasy as keyword instead of gemini

* close response body after draining

* remove \b from regex to support keys that end with -

* add \b to the beginning
2026-02-20 22:00:51 +05:00
Dylan AyreyandCursor Agent 952df702b3 Base64 decoding depth assessment (#4744)
* feat: iterative decoding pipeline with configurable depth

Decoders (base64, UTF-16, escaped unicode) now chain iteratively:
each decoder's output is fed back through all decoders until no new
transformations occur or --max-decode-depth is reached (default: 5).

This finds secrets hidden inside layered encodings, e.g. a base64
Docker auth blob containing a GCP private key, or a UTF-16 file
with base64-encoded credentials.

At depth=1 behavior is identical to the previous implementation.
Extra depths exit early when no new data is produced, so the cost
is <5% wall time on a large repo scan.

Co-authored-by: Dylan Ayrey <dxa4481@rit.edu>

* docs: iterative decoding performance data

Co-authored-by: Dylan Ayrey <dxa4481@rit.edu>

* comment: explain why PLAIN decoder is skipped at depth > 0

Co-authored-by: Dylan Ayrey <dxa4481@rit.edu>

* refactor: extract iterativeDecode, address review feedback

- Extract decode loop into standalone iterativeDecode() function,
  separating decoding from channel dispatch (rosecodym, camgunz).
- Drop decodeInput struct, use []byte directly (camgunz).
- Remove redundant maxDepth clamp from scannerWorker (camgunz).
- Inline decoderType variable (camgunz).
- Replace byteSliceSeen with slices.ContainsFunc (camgunz).

Co-authored-by: Dylan Ayrey <dxa4481@rit.edu>

* fix: remove unused decodeLatency metric (lint)

Co-authored-by: Dylan Ayrey <dxa4481@rit.edu>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-02-19 21:26:37 -08:00
meredith 3602bbed8a fix(release): Disable docker provenance feature (#4752)
Our underlying "ubuntu-latest" image moved to Docker v29, which defaults
to a containerd image store, which can store provenance info and creates
even single images with a manifest by default, but goreleaser with our
current config isn't expecting that.  This unblocks the release build,
but I believe moving to dockers_v2 will fully resolve.

See also: docker/build-push-action#755
2026-02-19 15:26:00 -08:00
meredith 1ffbefcea5 Add workspace_id to Slack Continuous metadata (#4749)
This is needed for EE Slack Continuous feature work, for archi reasons
it needs a change to the message here in OSS.
2026-02-19 09:29:48 -06:00
Shahzad Haider 7c0734f987 optimize the regex pattern in the artifactory access token detector (#4685) v3.93.4 2026-02-19 15:16:35 +01:00