Repository navigation
fix(filesystem): skip cache files by extension - #8112
Conversation
Original alert (resolved)Security Policy Alert: Secret Policy ViolationThis workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch. Secret references detected:
To approve this workflow, please add the Note: The label must be added by someone other than the PR author (cx-laura-rodrigues) or automation bots to ensure proper security review. After the label is added, you can re-run the blocked workflow to proceed. This workflow will be automatically approved once merged into the default branch. For more information, see StepSecurity's Secret Exfiltration Policy documentation. |
Security Policy Alert: Secret Policy ViolationThis workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch. Secret references detected:
To approve this workflow, please add the Note: The label must be added by someone other than the PR author (cx-laura-rodrigues) or automation bots to ensure proper security review. After the label is added, you can re-run the blocked workflow to proceed. This workflow will be automatically approved once merged into the default branch. For more information, see StepSecurity's Secret Exfiltration Policy documentation. |
cx-artur-ribeiro
left a comment
There was a problem hiding this comment.
Hi @cx-laura-rodrigues,
First of all, thanks for the contribution!
I believe the problem here is not catching .cache files, although I understand a similar solution was applied for terraform cache files on line 31 of pkg/engine/provider/filesystem.go.
The problem seems to be the misinterpretation of the files in question as belonging to the docker compose platform, when in fact they shouldn't be correlated to that platform.
KICS does not have an extension per se for docker compose files, so it goes through checkContent, which is used for json and yaml files that could belong to multiple platforms. Those files are then compared against multiple regexes to understand which platform the file content belongs to.
In this case, after scanning a file with the same content as your test files, I found that the problem is that the regex used for docker compose is too loose, causing it to match the content of a file that is not actually a docker compose file.
Below you can see the current regex compared to a file with similar content:
Additionally, if we had a different file name but the same content, we would still hit the same symptom your pull request addresses, since the file wouldn't be excluded by name.
For that reason, I would suggest making the regex more robust in analyzer.
For example, something along these lines:
dockerComposeServicesRegex = regexp.MustCompile(`(?m)^\s*"?services"?\s*:[\w\W]+^\s*"?(image|build)"?\s*:`)After testing and adding a new test file for this specific case, which I can also provide for testing purposes, I got no regressions on the files we already have enough observability into to know that KICS supports and scans correctly. We don't lose any results we already have and we fortify our content analysis by applying a better regex for comparison.
[
{
"offer": "sample-webservices",
"publisher": "checkmarx",
"sku": "sku1",
"urn": "checkmarx:sample-webservices:sku1:1.0.0",
"version": "1.0.0"
},
{
"offer": "sample-image",
"publisher": "checkmarx",
"sku": "sku2",
"urn": "checkmarx:sample-image:sku2:1.0.0",
"version": "1.0.0"
}
]Let me know what you think!
Thanks again for helping us improve kics! 🥳
|
| Secret Type | Status | Commit | File Path | View |
|---|---|---|---|---|
| Box | d610057226 |
.github/scripts/report/e2e-report |
🔎 View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Immediately rotate/revoke the exposed secret. (https://howtorotate.com/docs/introduction/getting-started/)
- Remove it from git history ( a new "remove secret" commit is NOT enough e.g. with
git-filter-repo).
To avoid such incidents in the future consider:
- Following the best practices for managing and storing secrets, including API keys and other credentials.
- Re-scan after cleanup before merging.
⚠️ These are unverified matches and do not block the merge — please review and confirm they are not real secrets.
Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
kics 2.2.0 Created-by: HarmonybrewBot Commit-by: HarmonybrewBot Merged-by: HarmonybrewBot Description: Created by `brew bump` --- Created with `brew bump-formula-pr`.<details> <summary>release notes</summary> <pre>## What's Changed * docs(release): update queries catalog, index and dockerfile for upcoming release by @cx-artur-ribeiro in Checkmarx/kics#8094 * fix(query): added missing case to "Last User is Root" Dockerfile query. by @cx-andre-pereira in Checkmarx/kics#8095 * feat(queries): new queries to check if synapse workspace managed virtual network is enabled by @cx-ricardo-jesus in Checkmarx/kics#8097 * refactor(descriptions): remove pkg/descriptions and related CLI flag by @cx-ricardo-jesus in Checkmarx/kics#8092 * CISO-1264 - Update GitHub Actions runner labels by @cx-jonathan-hartman in Checkmarx/kics#8093 * fix(query): Fix for Missing Backslash Support on Copy_With_More_Than_Two_Arguments_Not_Ending_With_Slash query by @cx-andre-pereira in Checkmarx/kics#8099 * fix(actions): refactor gh actions to fix CI by @cx-artur-ribeiro in Checkmarx/kics#8098 * fix(query): change to keyExpectedValue on ARM 'default_azure_storage_account_network_access_is_too_permissive' query by @cx-andre-pereira in Checkmarx/kics#8101 * update(version): rename VERSION build-arg to ENGINE_VERSION by @cx-artur-ribeiro in Checkmarx/kics#8102 * fix(query): correct keyExpectedValue and keyActualValue in redshift_not_encrypted by @cx-ricardo-jesus in Checkmarx/kics#8105 * fix(analyzer): bound file analysis workers by @omribz156 in Checkmarx/kics#8058 * fix(actions): remove outdated actions and update documentation accordingly by @cx-artur-ribeiro in Checkmarx/kics#8110 * fix(action): remove concurrent group from run projects github action by @cx-artur-ribeiro in Checkmarx/kics#8111 * fix(test): normalize timestamp comparison in TestInitCycloneDxReport by @cx-artur-ribeiro in Checkmarx/kics#8113 * fix(actions): fix security vulnerabilities and update ci with new enforced rules by @cx-artur-ribeiro in Checkmarx/kics#8118 * fix(release): gate kics release workflows behind release environment by @cx-lior-poterman in Checkmarx/kics#8108 * fix(validator): update queries validator for cwe and risk score fields by @cx-artur-ribeiro in Checkmarx/kics#8028 * fix(version): new available version with additional v prefix by @cx-artur-ribeiro in Checkmarx/kics#8119 * fix(analyzer): improvement to dockerfile scanning by @cx-andre-pereira in Checkmarx/kics#8114 * chore(release): removed unused goreleaser configuration files by @cx-ricardo-jesus in Checkmarx/kics#8122 * fix(filesystem): skip cache files by extension by @cx-laura-rodrigues in Checkmarx/kics#8112 * fix(query): changed all dockerfile queries for case insensitive support of dockerfile commands by @cx-andre-pereira in Checkmarx/kics#8115 * docs(release): update queries catalog, index and dockerfile for 2.2.0 by @cx-artur-ribeiro in Checkmarx/kics#8126 ## New Contributors * @cx-jonathan-hartman made their first contribution in Checkmarx/kics#8093 * @omribz156 made their first contribution in Checkmarx/kics#8058 * @cx-lior-poterman made their first contribution in Checkmarx/kics#8108 **Full Changelog**: https://github.com/Checkmarx/kics/compare/v2.1.21...v2.2.0</pre> <p>View the full release notes at <a href="https://github.com/Checkmarx/kics/releases/tag/v2.2.0">https://github.com/Checkmarx/kics/releases/tag/v2.2.0</a>.</p> </details> <hr> See merge request: Harmonybrew/homebrew-core!20473
* fix(filesystem): skip cache files by extension * fix: improvement to regex used for docker compose detection * Update pkg/analyzer/analyzer.go Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com> * fix: lint --------- Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
* fix(filesystem): skip cache files by extension * fix: improvement to regex used for docker compose detection * Update pkg/analyzer/analyzer.go Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com> * fix: lint --------- Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
Proposed Changes
.cache.extension/pattern during the filesystem walk, before they reach the parser..cache.files are excluded and no longer processed.Jira: AST-170544
I submit this contribution under the Apache-2.0 license.