4cc3f5bee4
Platform: moko-platform CI / Gate 2: Unit Tests (8.1) (push) Blocked by required conditions
Platform: moko-platform CI / Gate 2: Unit Tests (8.2) (push) Blocked by required conditions
Platform: moko-platform CI / Gate 2: Unit Tests (8.3) (push) Blocked by required conditions
Platform: moko-platform CI / Gate 3: Self-Health Check (push) Blocked by required conditions
Platform: moko-platform CI / Gate 4: Governance (push) Blocked by required conditions
Platform: moko-platform CI / Gate 2: Unit Tests (8.1) (pull_request) Blocked by required conditions
Platform: moko-platform CI / Gate 2: Unit Tests (8.2) (pull_request) Blocked by required conditions
Platform: moko-platform CI / Gate 2: Unit Tests (8.3) (pull_request) Blocked by required conditions
Platform: moko-platform CI / Gate 3: Self-Health Check (pull_request) Blocked by required conditions
Platform: moko-platform CI / Gate 4: Governance (pull_request) Blocked by required conditions
Generic: Repo Health / Site Health (push) Has been skipped
Generic: Repo Health / Access control (push) Successful in 2s
Universal: PR Check / Branch Policy (pull_request) Successful in 1s
Generic: Repo Health / Site Health (pull_request) Has been skipped
Generic: Repo Health / Access control (pull_request) Successful in 2s
Universal: PR Check / Validate PR (pull_request) Successful in 5s
Universal: Secret Scanning / Gitleaks Secret Scan (pull_request) Successful in 6s
Generic: Repo Health / Release configuration (push) Successful in 5s
Generic: Repo Health / Scripts governance (push) Successful in 5s
Generic: Repo Health / Release configuration (pull_request) Successful in 6s
Generic: Repo Health / Scripts governance (pull_request) Successful in 6s
Generic: Repo Health / Repository health (push) Successful in 14s
Generic: Repo Health / Repository health (pull_request) Successful in 12s
Platform: moko-platform CI / Gate 1: Code Quality (pull_request) Failing after 44s
Platform: moko-platform CI / Gate 1: Code Quality (push) Failing after 49s
Platform: moko-platform CI / Gate 5: Template Integrity (pull_request) Has been skipped
Platform: moko-platform CI / Gate 5: Template Integrity (push) Has been skipped
Platform: moko-platform CI / CI Summary (push) Has been cancelled
Platform: moko-platform CI / CI Summary (pull_request) Has been cancelled
- Convert tabs to spaces (3,413 violations) - Fix line endings, trailing whitespace, brace placement - Break lines exceeding 150-char absolute limit - Replace heredoc tab closers with spaces - Fix empty elseif, forbidden function calls - Update phpcs.xml: exclude rules inappropriate for CLI scripts (SideEffects, MissingNamespace, MultipleClasses, HeaderOrder, empty catch blocks) Authored-by: Moko Consulting Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
114 lines
3.8 KiB
PHP
114 lines
3.8 KiB
PHP
#!/usr/bin/env php
|
|
<?php
|
|
|
|
/* Copyright (C) 2026 Moko Consulting <hello@mokoconsulting.tech>
|
|
*
|
|
* This file is part of a Moko Consulting project.
|
|
*
|
|
* SPDX-License-Identifier: GPL-3.0-or-later
|
|
*
|
|
* FILE INFORMATION
|
|
* DEFGROUP: MokoStandards.Scripts.Validate
|
|
* INGROUP: MokoStandards
|
|
* REPO: https://git.mokoconsulting.tech/MokoConsulting/moko-platform
|
|
* PATH: /validate/check_no_secrets.php
|
|
* BRIEF: Checks for potential secrets in committed files (advisory)
|
|
*/
|
|
|
|
declare(strict_types=1);
|
|
|
|
require_once __DIR__ . '/../../vendor/autoload.php';
|
|
|
|
use MokoEnterprise\CliFramework;
|
|
|
|
/**
|
|
* Scans all tracked non-binary files for common secret patterns (advisory — always exits 0).
|
|
*/
|
|
class CheckNoSecrets extends CliFramework
|
|
{
|
|
/** Regex matching suspicious key=value or key: value assignments. */
|
|
private const SECRET_PATTERN = '/(password|api[_\-]?key|secret|token|private[_\-]?key)\s*[:=]\s*["\'][^"\']{8,}/i';
|
|
|
|
/**
|
|
* Substrings that mark a line as a known-safe false positive.
|
|
* Dolibarr CSRF token functions generate nonces at runtime — not credentials.
|
|
*/
|
|
private const SAFE_SUBSTRINGS = ['newToken()', 'checkToken()', 'currentToken()'];
|
|
|
|
/** Binary file extensions to skip. */
|
|
private const BINARY_EXTENSIONS = ['jpg', 'jpeg', 'png', 'gif', 'pdf', 'zip', 'tar', 'gz'];
|
|
|
|
/**
|
|
* Configure available arguments.
|
|
*/
|
|
protected function configure(): void
|
|
{
|
|
$this->setDescription('Checks for potential secrets in committed files (advisory)');
|
|
$this->addArgument('--path', 'Repository path to check', '.');
|
|
}
|
|
|
|
/**
|
|
* Run the secrets scan (advisory — always exits 0).
|
|
*
|
|
* @return int Exit code: always 0.
|
|
*/
|
|
protected function run(): int
|
|
{
|
|
$path = $this->getArgument('--path');
|
|
$output = shell_exec('git -C ' . escapeshellarg($path) . ' ls-files 2>/dev/null') ?? '';
|
|
$all = array_values(array_filter(explode("\n", $output)));
|
|
$files = array_filter($all, function (string $f): bool {
|
|
return !in_array(strtolower(pathinfo($f, PATHINFO_EXTENSION)), self::BINARY_EXTENSIONS, true);
|
|
});
|
|
$files = array_values($files);
|
|
$total = count($files);
|
|
$found = 0;
|
|
|
|
$this->section('Scanning for secret patterns');
|
|
|
|
foreach ($files as $i => $file) {
|
|
$this->progress($i + 1, $total, $file);
|
|
$fullPath = $path . '/' . $file;
|
|
if (!is_file($fullPath)) {
|
|
continue;
|
|
}
|
|
$lines = explode("\n", (string) file_get_contents($fullPath));
|
|
$flagged = false;
|
|
foreach ($lines as $line) {
|
|
if (!preg_match(self::SECRET_PATTERN, $line)) {
|
|
continue;
|
|
}
|
|
// Skip known-safe patterns (e.g. Dolibarr CSRF token functions)
|
|
$safe = false;
|
|
foreach (self::SAFE_SUBSTRINGS as $sub) {
|
|
if (str_contains($line, $sub)) {
|
|
$safe = true;
|
|
break;
|
|
}
|
|
}
|
|
if (!$safe) {
|
|
$flagged = true;
|
|
break;
|
|
}
|
|
}
|
|
if ($flagged) {
|
|
$this->progress($i + 1, $total, '', true);
|
|
$this->status(false, $file, 'potential secret pattern detected');
|
|
$found++;
|
|
}
|
|
}
|
|
$this->progress($total, $total, '', true);
|
|
|
|
$this->printSummary($total - $found, $found, $this->elapsed());
|
|
|
|
if ($found > 0) {
|
|
$this->log('WARNING', 'Advisory — review flagged files manually');
|
|
}
|
|
|
|
return 0;
|
|
}
|
|
}
|
|
|
|
$script = new CheckNoSecrets('check_no_secrets', 'Checks for potential secrets in committed files');
|
|
exit($script->execute());
|