Skip to content

Commit

Permalink
Azure function key is throwing FPs (#2352)
Browse files Browse the repository at this point in the history
* Merge branch 'main' of github.com:trufflesecurity/trufflehog

* AZF throwing FPs

* update snifftest script
  • Loading branch information
dustin-decker committed Jan 29, 2024
1 parent 7befefd commit 453792d
Show file tree
Hide file tree
Showing 2 changed files with 3 additions and 4 deletions.
4 changes: 2 additions & 2 deletions hack/snifftest/snifftest.sh
Original file line number Diff line number Diff line change
Expand Up @@ -8,8 +8,8 @@ REPO_ARRAY=(
# "https://github.com/Netflix/dgs-framework.git"
# "https://github.com/Netflix/vector.git"
# "https://github.com/expressjs/express.git"
"https://github.com/Azure/azure-sdk-for-net"
"https://github.com/Azure/azure-cli"
# "https://github.com/Azure/azure-sdk-for-net"
# "https://github.com/Azure/azure-cli"
)
REPOS=$(printf "%s," "${REPO_ARRAY[@]}" | cut -d "," -f 1-${#REPO_ARRAY[@]})
go run hack/snifftest/main.go scan --exclude privatekey --exclude uri --exclude github_old --repo "$REPOS" --detector all --print --fail-threshold 99
3 changes: 1 addition & 2 deletions pkg/engine/defaults.go
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,6 @@ import (
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/azurebatch"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/azurecontainerregistry"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/azuredevopspersonalaccesstoken"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/azurefunctionkey"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/azuresearchadminkey"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/azuresearchquerykey"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/azurestorage"
Expand Down Expand Up @@ -1608,7 +1607,7 @@ func DefaultDetectors() []detectors.Detector {
azurestorage.Scanner{},
azurecontainerregistry.Scanner{},
azurebatch.Scanner{},
azurefunctionkey.Scanner{},
// azurefunctionkey.Scanner{}, // detector is throwing some FPs
azuredevopspersonalaccesstoken.Scanner{},
azuresearchadminkey.Scanner{},
&azuresearchquerykey.Scanner{},
Expand Down

0 comments on commit 453792d

Please sign in to comment.