Commit Graph
74 Commits
Author SHA1 Message Date
Mustansir daf5bf1e94 [INS-280] Fix Github "repostories" filter does not respect GHES endpoint (#4677) 2026-02-04 11:17:55 +05:00
Mustansir b3b1d4180a [INS-258] Revert includeRepos removal from GitHub source (#4673)
* Revert "Remove include repos (#4469)"

This reverts commit 24c73b0cb6.

* generate protos

* preserve tests for repositories
2026-01-27 19:01:50 +05:00
Mustansir 2fdab87df9 bug fix: UnitErr and UnitOK called for the same repo (#4681) 2026-01-27 19:00:31 +05:00
Pascal THUET 37994c5d59 fix(github): preserve trailing hyphens in repository names (#4695)
Fix a bug where repository names ending with a hyphen (e.g., "my-repo-")
would have the trailing hyphen stripped when parsing the URL, causing
404 errors when trying to access the repository via the GitHub API.

The issue was in getRepoURLParts() which reconstructed the URL via
url.URL.String() and then re-parsed it. This process could lose
trailing special characters in some cases.

The fix uses repoURL.Host and repoURL.Path directly instead of
reconstructing via String(), which preserves the original path
including any trailing hyphens.

Fixes #4679
2026-01-26 09:50:20 -05:00
Jordan Tunstill 24c73b0cb6 Remove include repos (#4469)
* Removed redundant IncludeRepos mentions.

* removed proto for IncludeRepos and remade protos

* removed another instance of includeRepos

* reverted proto removal and

* actually deprecated the field

* ran make protos
2025-10-21 15:28:12 -07:00
Jordan TunstillandKashif Khan 0f60f6ecfe explicit repositories now bypass wantRepo() filtering entirely. added ctx to newConnector (#4507)
* explicit repositories now bypass wantRepo() filtering entirely.
added ctx to newConnector

* Added test that demonstrates this bypass

* simplified test and focused on enumeration

---------

Co-authored-by: Kashif Khan <70996046+kashifkhan0771@users.noreply.github.com>
2025-10-21 15:27:26 -07:00
jordanTunstill a66d9e75c2 Changes to fix Enterprise UI filtering of Github Hosted Scanner Repositories to Include (#4430)
* Changes to fix Enterprise UI filtering of Github Hosted Scanner Repositories to Include

* trying to pass linting isssues

* trying to solve linting errors

* Added upstream repo filtering, improvements to normalizeRepo, and unit tests for both.

* Fixing tests impacted by PR 4426
2025-09-03 13:16:39 -07:00
Kashif Khan 000d748651 Scan Github Private Repositories With Token (#4426)
* Scan Github private repositories with Authenticated user

* readded some old comments

* resolved comments

* resolved linter

* Added comment
2025-09-01 18:30:08 +05:00
Kashif Khan 6f36a477c6 Added a dedicated optional flag to ignore gists during scan (#4423)
* Added a dedicated optional flag to ignore gists during scan

* added test case
2025-08-25 16:07:05 +05:00
0x1 3ee9c2f1af [SCAN-165] Use Err Reporting (#3862)
* nit

* update rate limit handler to use reporter

* update process repos to use rate limit handler with unit reporter

* update getReposByOrgOrUser to report err

* update dedupreporter to report err

* add errReporter interface to handle both types of reporters

* convert to error reporter types

* update handleRateLimit signature

* use reporters for all rate limit handlers in github

* get repo url before err check

* use iterator

* remove err log

* nit

* pluralize

* remove err log

* update tests

* make linter happy
2025-02-04 13:44:37 -05:00
ahrav e2f5e0e4bc upgrade Github dep (#3699) 2024-12-02 12:34:47 -08:00
trufflesteeeve 3c69bbc74f Separate org listing error from finding 0 members error cases (#3654) 2024-11-22 11:29:32 -05:00
JonZeollaandZachary Rice 4ea311dea9 feat: add github comments timeframe filtering (fixes #3388) (#3390)
* feat: add github comments timeframe filtering

* fixup and generate protos

* Cleanup

---------

Co-authored-by: Zachary Rice <zachary.rice@trufflesec.com>
2024-10-15 15:13:36 -04:00
ahrav e57c712998 Manually upgrade github dep (#3387) 2024-10-10 06:16:40 -07:00
ahrav b63d6c02a7 [chore] - Rename memory cache package to 'simple' for clarity (#3352)
* rename memory to cache

* Update

* fix imports
2024-10-02 07:48:26 -07:00
Miccah 2f3a410e38 Implement SourceUnitEnumChunker for GitHub (#3298)
* Implement SourceUnitEnumChunker for GitHub

This change refactors the internal scan method to introduce a scanRepo
method to perform the actual scan.

* Export unit fields so the values are captured in the report

* Add comment for scanRepo

* Break out ensureRepoInfoCache into a method

* Update comments and check errors

* Ensure that the repoInfoCache contains the repo during ChunkUnit

* Add integration test for ChunkUnit

* Move s.scanOptions initialization to Init()
2024-09-23 10:56:55 -07:00
Miccah 77dc2720a8 Update GitHub enumeration to report unique filtered values (#3292)
The reported values should match the values populated in s.repos.
2024-09-18 14:30:10 -07:00
Miccah e89190f3ed Instrument GitHub source with a UnitReporter (#3284)
* Fix GitHub integration test

* Instrument GitHub source with a UnitReporter

The reporter is currently unused, but is the first step to support
scanning while enumerating.

* Update GitHub unit tests
2024-09-12 10:28:37 -07:00
Nash 17f6c98119 GitHub source logger clean up (#3269)
* GitHub source logger clean up

* applied pr comments

* applied pr comments

* applied pr comments

* applied PR review comments
2024-09-09 15:44:56 -04:00
Cody Rose f26b502c2e Auth GitHub in Init (#3131)
The GitHub source currently applies its authentication configuration as the first step of enumeration. This is incompatible with both targeted scans and scan job reports, and also means that authentication logic has to be duplicated into the validation flow. This PR moves it into Init so that it's available to targeted scans and, eventually, unit-specific scans. This also allows us to remove the copy of the old logic that was in Validate.

As part of the work I've also cleaned up the integration test suite. (Several of them were apparently disabled back when they ran on every push, but now that we're not doing that, we can re-enable them.)
2024-08-05 15:13:29 -04:00
ahrav 55fe05d0b4 fix dep versions (#3106) 2024-07-26 17:44:23 -07:00
Cody Rose de19a39f2c Return targeted scan errors (#2995)
Targeted scans should return their errors so that consumers can process them. By creating a type that combines an error with a targeted secret ID, we can return these errors without having to modify the Source interface.
2024-06-21 13:50:56 -04:00
Richard Gomez 5216142960 refactor(cache): use generics (#2930) 2024-06-06 13:08:00 -04:00
Richard Gomez 9053d8f4de refactor(github): enumerateWithToken flow & tests (#2880) 2024-05-31 15:53:44 -05:00
Richard Gomez 5102e3ae11 test(github): fix some errors (#2774) 2024-05-24 13:03:41 -07:00
Richard Gomez e53f5bd5c5 Improve handling of Gist URLs (#2653)
* feat(github): handle ghes gists

* fix(github): handle all gist URLs

* refactor(github): helper func to check gist urls
2024-05-24 08:36:30 -07:00
ahrav 896e6e7c66 upgrade github dep (#2858) 2024-05-16 14:35:08 -07:00
ahrav a8132839f8 [chore] - update go-github dep manually (#2664)
* update go-github dep

* remove commented out line
2024-04-03 19:19:14 -07:00
Richard Gomez 3b58a15a84 Fix GitHub enumeration & rate-limiting logic (#2625)
This is a follow-up to #2379.

It fixes the following issues:

GitHub API calls missing rate-limit handling
The fix for Refactor GitHub source #2379 (comment) inadvertently resulting in duplicate API calls
2024-03-29 10:29:46 -04:00
Richard Gomez 95dc8d6e16 Fix additional GitHub test errors #2614 2024-03-26 09:34:12 -04:00
Richard Gomez 9d4cf87c02 fix(github): resolve panic & test failures (#2608) 2024-03-22 09:49:01 -07:00
Richard GomezandBill Rich 80e8a67c2d Refactor GitHub source (#2379)
* refactor(github): cleanup logic

* fix(github): lookup wikis per-repo

* refactor(github): change scanErrs.String output

---------

Co-authored-by: Bill Rich <bill.rich@gmail.com>
2024-03-21 14:07:39 -07:00
Richard Gomez b3ff12d1e9 Fix handling of GitHub ratelimit information (#2041)
This is a follow-up to #1912, which used the headers from the response to determine rate-limiting information, instead of using the values from RateLimitError.Rate. Although that logic seemed solid, I discovered that it did not work in some circumstances. This lead to the "unexpected" path more often than intended, and periodic instances where requests would be made before the ratelimit was refreshed.
2024-02-07 09:11:12 -05:00
ahrav 3d2490ca80 use Repositories field from conn. (#1860) 2023-10-04 13:56:02 -07:00
ahrav 22876f8381 replace interface{} with any. (#1771) 2023-09-15 04:35:15 -07:00
ahrav d51e3b6d83 Only scan gist comments or repo comments. (#1646) 2023-08-20 11:38:28 -07:00
ahrav 0ae8cf5d35 [bug] - handle IOOR panic (#1639)
* handle IOOR panic.

* use a better fxn name.

* increae timeout for test to compete.

* simplify code and add test.

* do it for miccah.
2023-08-17 15:47:11 -07:00
Richard Gomez 2290954b02 fix(github): use apiEndpoint for basic or no auth (#1454) 2023-07-25 20:03:08 -07:00
ahrav 1da7720912 Replace context.TODO. (#1349) 2023-05-19 11:09:51 -07:00
ahrav 31844b12e3 [oc-313] - Add GitHub metrics (#1324)
* Normalize repos during enumeration.

* fix test.

* Add benchmark.

* Add benchmark.

* Add more realistic benchmark values.

* add gist mocks.

* Remove old normalize fxn.

* abstract away the repo cache.

* update test.

* increase repo count.

* increase page limnit to 100.

* move callee fxns below caller for Chunks.

* Add context to normalize.

* remove extra logic in normalize repo.

* Delete new.txt

* Delete old.txt

* Handle errors in a thread safe manner.

* fix test.'

* fix test.

* handle repos that are included by users.

* Abstract include ignore logic within repoCache.

* Add better comment around repoCache.

* Rename params.

* remove commented out code.

* use repos instead of items.

* remove commented out code.

* Use ++ instead of atomic increment.

* update to use logger var.

* use cache pkg.

* Use separate file for repo logic.

* Address comments.

* fix test.

* make less sucky test.

* Update test.

* Add logs for duration and repo size.

* fix integration test.

* address comment.
2023-05-16 08:45:28 -07:00
ahrav 030c093392 Fix how we scan orgs (#1327)
* Fix how we scan orgs.

* fix integration test.
2023-05-04 08:07:11 -07:00
ahrav 323c093818 Normalize GitHub repos during enumeration (#1269)
* Normalize repos during enumeration.

* fix test.

* Add benchmark.

* Add benchmark.

* Add more realistic benchmark values.

* add gist mocks.

* Remove old normalize fxn.

* abstract away the repo cache.

* update test.

* increase repo count.

* increase page limnit to 100.

* move callee fxns below caller for Chunks.

* Add context to normalize.

* remove extra logic in normalize repo.

* Delete new.txt

* Delete old.txt

* Handle errors in a thread safe manner.

* fix test.'

* fix test.

* handle repos that are included by users.

* Abstract include ignore logic within repoCache.

* Add better comment around repoCache.

* Rename params.

* remove commented out code.

* use repos instead of items.

* remove commented out code.

* Use ++ instead of atomic increment.

* update to use logger var.

* use cache pkg.

* Address comments.

* fix test.

* make less sucky test.

* Update test.
2023-05-03 08:35:53 -07:00
ahrav a2266b4e28 add additional logging (#1298)
* add additional logging.

* update test.

* remove continue.

* address comments.
2023-04-27 16:48:04 -07:00
Miccah 0ce72ccda3 [chore] Remove logrus from github source (#1086)
* [chore] Remove logrus from github source

* Fix handleRateLimit test

* Fix tests
2023-02-09 18:02:04 -06:00
Dustin Decker 4ef546a06b fix github integration tests (#1042) 2023-01-25 08:57:39 -08:00
ahrav 936a139596 Allow using a glob for include list. (#977)
* Allow using a glob for include list.

* Update command flag.

* Make comment more clear.

* update comment.

* Allow scanning repo and org at the same time.
2022-12-16 13:28:16 -08:00
Dustin Decker 7de9bdd12d Support globbing with ignore repos (#967) 2022-12-09 12:10:42 -08:00
ahrav a72b9feb35 Only scan org with --org flag. (#931) 2022-12-06 16:18:48 -08:00
ahrav 46bc010165 Add tests for including github repos. (#854) 2022-10-21 07:56:36 -07:00
ahrav 2d6aadcb46 [THOG-774] - GitHub ignore repo full name (#848)
* Use github repo full name.

* fix tests.
2022-10-14 09:20:49 -07:00