Files
Jonathan Miller 4cc3f5bee4
Platform: moko-platform CI / Gate 2: Unit Tests (8.1) (push) Blocked by required conditions
Platform: moko-platform CI / Gate 2: Unit Tests (8.2) (push) Blocked by required conditions
Platform: moko-platform CI / Gate 2: Unit Tests (8.3) (push) Blocked by required conditions
Platform: moko-platform CI / Gate 3: Self-Health Check (push) Blocked by required conditions
Platform: moko-platform CI / Gate 4: Governance (push) Blocked by required conditions
Platform: moko-platform CI / Gate 2: Unit Tests (8.1) (pull_request) Blocked by required conditions
Platform: moko-platform CI / Gate 2: Unit Tests (8.2) (pull_request) Blocked by required conditions
Platform: moko-platform CI / Gate 2: Unit Tests (8.3) (pull_request) Blocked by required conditions
Platform: moko-platform CI / Gate 3: Self-Health Check (pull_request) Blocked by required conditions
Platform: moko-platform CI / Gate 4: Governance (pull_request) Blocked by required conditions
Generic: Repo Health / Site Health (push) Has been skipped
Generic: Repo Health / Access control (push) Successful in 2s
Universal: PR Check / Branch Policy (pull_request) Successful in 1s
Generic: Repo Health / Site Health (pull_request) Has been skipped
Generic: Repo Health / Access control (pull_request) Successful in 2s
Universal: PR Check / Validate PR (pull_request) Successful in 5s
Universal: Secret Scanning / Gitleaks Secret Scan (pull_request) Successful in 6s
Generic: Repo Health / Release configuration (push) Successful in 5s
Generic: Repo Health / Scripts governance (push) Successful in 5s
Generic: Repo Health / Release configuration (pull_request) Successful in 6s
Generic: Repo Health / Scripts governance (pull_request) Successful in 6s
Generic: Repo Health / Repository health (push) Successful in 14s
Generic: Repo Health / Repository health (pull_request) Successful in 12s
Platform: moko-platform CI / Gate 1: Code Quality (pull_request) Failing after 44s
Platform: moko-platform CI / Gate 1: Code Quality (push) Failing after 49s
Platform: moko-platform CI / Gate 5: Template Integrity (pull_request) Has been skipped
Platform: moko-platform CI / Gate 5: Template Integrity (push) Has been skipped
Platform: moko-platform CI / CI Summary (push) Has been cancelled
Platform: moko-platform CI / CI Summary (pull_request) Has been cancelled
style: fix all PHPCS PSR-12 violations across 74 files (7539 → 0 errors)
- Convert tabs to spaces (3,413 violations)
- Fix line endings, trailing whitespace, brace placement
- Break lines exceeding 150-char absolute limit
- Replace heredoc tab closers with spaces
- Fix empty elseif, forbidden function calls
- Update phpcs.xml: exclude rules inappropriate for CLI scripts
  (SideEffects, MissingNamespace, MultipleClasses, HeaderOrder,
  empty catch blocks)

Authored-by: Moko Consulting
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-05-24 17:07:51 -05:00

114 lines
3.8 KiB
PHP

#!/usr/bin/env php
<?php
/* Copyright (C) 2026 Moko Consulting <hello@mokoconsulting.tech>
*
* This file is part of a Moko Consulting project.
*
* SPDX-License-Identifier: GPL-3.0-or-later
*
* FILE INFORMATION
* DEFGROUP: MokoStandards.Scripts.Validate
* INGROUP: MokoStandards
* REPO: https://git.mokoconsulting.tech/MokoConsulting/moko-platform
* PATH: /validate/check_no_secrets.php
* BRIEF: Checks for potential secrets in committed files (advisory)
*/
declare(strict_types=1);
require_once __DIR__ . '/../../vendor/autoload.php';
use MokoEnterprise\CliFramework;
/**
* Scans all tracked non-binary files for common secret patterns (advisory — always exits 0).
*/
class CheckNoSecrets extends CliFramework
{
/** Regex matching suspicious key=value or key: value assignments. */
private const SECRET_PATTERN = '/(password|api[_\-]?key|secret|token|private[_\-]?key)\s*[:=]\s*["\'][^"\']{8,}/i';
/**
* Substrings that mark a line as a known-safe false positive.
* Dolibarr CSRF token functions generate nonces at runtime — not credentials.
*/
private const SAFE_SUBSTRINGS = ['newToken()', 'checkToken()', 'currentToken()'];
/** Binary file extensions to skip. */
private const BINARY_EXTENSIONS = ['jpg', 'jpeg', 'png', 'gif', 'pdf', 'zip', 'tar', 'gz'];
/**
* Configure available arguments.
*/
protected function configure(): void
{
$this->setDescription('Checks for potential secrets in committed files (advisory)');
$this->addArgument('--path', 'Repository path to check', '.');
}
/**
* Run the secrets scan (advisory — always exits 0).
*
* @return int Exit code: always 0.
*/
protected function run(): int
{
$path = $this->getArgument('--path');
$output = shell_exec('git -C ' . escapeshellarg($path) . ' ls-files 2>/dev/null') ?? '';
$all = array_values(array_filter(explode("\n", $output)));
$files = array_filter($all, function (string $f): bool {
return !in_array(strtolower(pathinfo($f, PATHINFO_EXTENSION)), self::BINARY_EXTENSIONS, true);
});
$files = array_values($files);
$total = count($files);
$found = 0;
$this->section('Scanning for secret patterns');
foreach ($files as $i => $file) {
$this->progress($i + 1, $total, $file);
$fullPath = $path . '/' . $file;
if (!is_file($fullPath)) {
continue;
}
$lines = explode("\n", (string) file_get_contents($fullPath));
$flagged = false;
foreach ($lines as $line) {
if (!preg_match(self::SECRET_PATTERN, $line)) {
continue;
}
// Skip known-safe patterns (e.g. Dolibarr CSRF token functions)
$safe = false;
foreach (self::SAFE_SUBSTRINGS as $sub) {
if (str_contains($line, $sub)) {
$safe = true;
break;
}
}
if (!$safe) {
$flagged = true;
break;
}
}
if ($flagged) {
$this->progress($i + 1, $total, '', true);
$this->status(false, $file, 'potential secret pattern detected');
$found++;
}
}
$this->progress($total, $total, '', true);
$this->printSummary($total - $found, $found, $this->elapsed());
if ($found > 0) {
$this->log('WARNING', 'Advisory — review flagged files manually');
}
return 0;
}
}
$script = new CheckNoSecrets('check_no_secrets', 'Checks for potential secrets in committed files');
exit($script->execute());