Files
Patrick ErichsenandGitHub ff98dd93f5 ci: scan pull requests with TruffleHog (#111935)
* ci: scan pull requests with TruffleHog

* ci: scan staged changes with TruffleHog

* ci: fetch pull request base for secret scan

* ci: fetch complete pull request scan history
2026-07-20 17:08:41 -07:00

92 lines
2.5 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
ROOT_DIR="$(git rev-parse --show-toplevel 2>/dev/null || pwd)"
RUN_NODE_TOOL="$ROOT_DIR/scripts/pre-commit/run-node-tool.sh"
FILTER_FILES="$ROOT_DIR/scripts/pre-commit/filter-staged-files.mjs"
if [[ ! -x "$RUN_NODE_TOOL" ]]; then
echo "Missing helper: $RUN_NODE_TOOL" >&2
exit 1
fi
if [[ ! -f "$FILTER_FILES" ]]; then
echo "Missing helper: $FILTER_FILES" >&2
exit 1
fi
GIT_DIR="$(git rev-parse --git-dir 2>/dev/null || true)"
if [[ -n "$GIT_DIR" ]] && \
{ [[ -f "$GIT_DIR/MERGE_HEAD" ]] || \
[[ -f "$GIT_DIR/CHERRY_PICK_HEAD" ]] || \
[[ -f "$GIT_DIR/REVERT_HEAD" ]] || \
[[ -f "$GIT_DIR/REBASE_HEAD" ]] || \
[[ -d "$GIT_DIR/rebase-merge" ]] || \
[[ -d "$GIT_DIR/rebase-apply" ]]; }; then
# Sequencer commits stage the operation result, not just the user's local edits.
exit 0
fi
# Security: avoid option-injection from malicious file names (e.g. "--all", "--force").
# Robustness: NUL-delimited file list handles spaces/newlines safely.
# Compatibility: use read loops instead of `mapfile` so this runs on macOS Bash 3.x.
files=()
while IFS= read -r -d '' file; do
files+=("$file")
done < <(git diff --cached --name-only --diff-filter=ACMR -z)
if [ "${#files[@]}" -eq 0 ]; then
exit 0
fi
if ! command -v trufflehog >/dev/null 2>&1; then
cat >&2 <<'EOF'
OpenClaw requires TruffleHog for pre-commit secret scanning.
Install it, then retry the commit:
macOS: brew install trufflehog
Other platforms: https://github.com/trufflesecurity/trufflehog#installation
EOF
exit 1
fi
restage_files=()
for file in "${files[@]}"; do
if ! git check-ignore --no-index -q -- "$file"; then
restage_files+=("$file")
fi
done
format_files=()
while IFS= read -r -d '' file; do
format_files+=("$file")
done < <(node "$FILTER_FILES" format -- "${restage_files[@]}")
if [ "${#format_files[@]}" -gt 0 ]; then
"$RUN_NODE_TOOL" oxfmt --write --no-error-on-unmatched-pattern "${format_files[@]}"
fi
if [ "${#restage_files[@]}" -gt 0 ]; then
git add -- "${restage_files[@]}"
fi
staged_snapshot="$(mktemp -d "${TMPDIR:-/tmp}/openclaw-trufflehog.XXXXXX")"
trap 'rm -rf "$staged_snapshot"' EXIT
for file in "${files[@]}"; do
if [[ "$(git cat-file -t ":0:$file")" != "blob" ]]; then
continue
fi
snapshot_path="$staged_snapshot/$file"
mkdir -p "${snapshot_path%/*}"
git cat-file blob ":0:$file" > "$snapshot_path"
done
trufflehog \
--no-update \
--no-color \
--results=verified,unknown \
--fail \
--fail-on-scan-errors \
filesystem "$staged_snapshot"