-
Notifications
You must be signed in to change notification settings - Fork 54
pre commit hook
Credential Digger can be used as a pre-commit hook with the pre-commit framework. The hook scans the staged files of a repository looking for possible leaks before they get committed. If the commit is clean (i.e., it does not contain discoveries), the hook will be successful and the files will be commited as expected. In case the commit contains leaks, the hook will ask the user a confirmation whether to ignore the alerts or block the commit. It is possible also to execute silently the commit verification avoiding any interaction, and causing the hook to fail and abort the commit in case of discoveries. Credential Digger hook can also be used in CLI.
The hook if fully functioning when committing via terminal.
Please note that committing through VS Code or some other IDE can cause problems, e.g., a pre-commit not found message.
The pre-commit framework installs the hook in $HOME/.cache/pre-commit/repo. The cache is not automatically deleted but it can be done easily. To change the installation folder of the hooks set PRE_COMMIT_HOME (ref., Managing CI caches).
The location of SQLite db is set in $HOME/.local/data.db by default. This path can be changed, but please do not use ~ or relative paths.
If the folder containing the database data.db is in the repo that is scanned the hook will change the db and so the repo; by definition the hook will fail if the repo is modified by the hook itself so use another location.
Install pre-commit with pip install pre-commit
To delete the pre-commit environment use pre-commit clean.
Please note the hook uses a db and a set of rules. If you use the hook for the first time (or change the database), be it either with the pre-commit framwork or by CLI, you have to set the rules you wish to use.
Create .pre-commit-config.yaml in the root of your repository:
repos:
- repo: https://github.com/SAP/credential-digger
rev: main
hooks:
- id: credential-digger-hook
To avoid the warning of rev mutable reference, use rev: *release* e.g., rev: v4.7.0
Use pre-commit install to install the hook in repo/.git/hooks/pre-commit
During the first commit the hook will install Credential Digger and all its dependencies in the repo's environment (that will be re-used for the following commits).
It is possible to install immediately the environment using pre-commit install --install-hooks. The environment set up will require several minutes.
It is also possible to specify the location of the database and the rules used to scan the files.
To implement this configuration change the .pre-commit-config.yaml as follows:
repos:
- repo: https://github.com/SAP/credential-digger
rev: main
hooks:
- id: credential-digger-hook
args: [hook, --rules=/path/to/rules/my_hook_rules.yml, --db_path=/path/to/db/my_hook_db.db]
If you wish to use only the --rules or -dp_path option, remove the other one but keep the hook argument in the first position.
The hook, in case of discoveries will ask you to continue or to abort the commit. To remove this interaction modify the args field: args: [hook, ..., --no_interaction, ...]
It is possible to use the hook also cloning Credential Digger
git clone https://github.com/SAP/credential-digger
Then, change the repo field of .pre-commit-config.yaml in repo: /path/to/repo/credentialdigger
To install the hook globally, for current and future repositories:
If git global has not been set yet:
git config --global init.templateDir ~/.git-template
Then:
pre-commit init-templatedir ~/.git-template in the same folder where is .pre-commit-config.yaml
git init will initialize a repository with the credential digger hook already installed (a .pre-commit-config.yaml has to be in the repo)
It is possible to commit without launching the hook (so skipping it) with one of these two commands:
-
git commit -m "commit msg" -nIt will bypass pre-commit and commit-msg hooks -
SKIP=credential-digger-hook git commit -m "commit msg"It will bypass only credential-digger-hook
Inside the repo containing .pre-commit-config.yaml
Using a temp environment
pre-commit try-repo /path/to/crendentialdigger_repo
Using real environment
pre-commit run
Credential Digger hook can be also tested without the pre-commit framework.
First install Credential Digger with pip install credentialdigger
Use credentialdigger hook to run the scan on staged files.
Supported options:
--rules RULES Specify the yaml file path containing the scan rules
e.g., /path/to/rules.yaml
--db_path DB_PATH Specify the database file path where to save the results
e.g., /path/to/data.db
--no_interaction Flag used to remove the interaction i.e.,
do not prompt if the commit should continue
in case of discoveries. If specified, the hook will
fail in case of discoveries.
- Installation instructions: Readme
- Preparation for the scanner's rules
- Deploy over HTTPS (Optional)
- How to update the project
- How to install on MacOS ARM
- Python library
- CLI
- Web UI through the Docker installation
- Pre-commit hook