Skip to content

fix(filesystem): skip cache files by extension - #8112

Merged
cx-alon-rosenhek merged 4 commits into
masterfrom
AST-170544
Sep 16, 2026
Merged

cx-alon-rosenhek merged 4 commits into
masterfrom
AST-170544

Conversation

@cx-laura-rodrigues

Copy link
Copy Markdown
Contributor

Proposed Changes

  • Skip files matching the .cache. extension/pattern during the filesystem walk, before they reach the parser.
  • Added unit test coverage confirming .cache. files are excluded and no longer processed.

Jira: AST-170544

I submit this contribution under the Apache-2.0 license.

@stepsecurity-app

stepsecurity-app Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

✅ Resolved — a later workflow run passed this policy check.

Original alert (resolved)

Security Policy Alert: Secret Policy Violation

This workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch.

Secret references detected:

  • secrets.KICS_BOT_PAT at line 98
  • secrets.GITHUB_TOKEN at line 99

To approve this workflow, please add the workflows-approved label to this PR.

Note: The label must be added by someone other than the PR author (cx-laura-rodrigues) or automation bots to ensure proper security review.

After the label is added, you can re-run the blocked workflow to proceed.

This workflow will be automatically approved once merged into the default branch.

For more information, see StepSecurity's Secret Exfiltration Policy documentation.

@stepsecurity-app

Copy link
Copy Markdown
Contributor

Security Policy Alert: Secret Policy Violation

This workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch.

Secret references detected:

  • secrets.KICS_BOT_PAT at line 26

To approve this workflow, please add the workflows-approved label to this PR.

Note: The label must be added by someone other than the PR author (cx-laura-rodrigues) or automation bots to ensure proper security review.

After the label is added, you can re-run the blocked workflow to proceed.

This workflow will be automatically approved once merged into the default branch.

For more information, see StepSecurity's Secret Exfiltration Policy documentation.

@cx-artur-ribeiro cx-artur-ribeiro left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @cx-laura-rodrigues,
First of all, thanks for the contribution!

I believe the problem here is not catching .cache files, although I understand a similar solution was applied for terraform cache files on line 31 of pkg/engine/provider/filesystem.go.
The problem seems to be the misinterpretation of the files in question as belonging to the docker compose platform, when in fact they shouldn't be correlated to that platform.

Image

KICS does not have an extension per se for docker compose files, so it goes through checkContent, which is used for json and yaml files that could belong to multiple platforms. Those files are then compared against multiple regexes to understand which platform the file content belongs to.

In this case, after scanning a file with the same content as your test files, I found that the problem is that the regex used for docker compose is too loose, causing it to match the content of a file that is not actually a docker compose file.
Below you can see the current regex compared to a file with similar content:

Image

Additionally, if we had a different file name but the same content, we would still hit the same symptom your pull request addresses, since the file wouldn't be excluded by name.
For that reason, I would suggest making the regex more robust in analyzer.

For example, something along these lines:

dockerComposeServicesRegex                      = regexp.MustCompile(`(?m)^\s*"?services"?\s*:[\w\W]+^\s*"?(image|build)"?\s*:`)

After testing and adding a new test file for this specific case, which I can also provide for testing purposes, I got no regressions on the files we already have enough observability into to know that KICS supports and scans correctly. We don't lose any results we already have and we fortify our content analysis by applying a better regex for comparison.

[
  {
    "offer": "sample-webservices",
    "publisher": "checkmarx",
    "sku": "sku1",
    "urn": "checkmarx:sample-webservices:sku1:1.0.0",
    "version": "1.0.0"
  },
  {
    "offer": "sample-image",
    "publisher": "checkmarx",
    "sku": "sku2",
    "urn": "checkmarx:sample-image:sku2:1.0.0",
    "version": "1.0.0"
  }
]

Let me know what you think!
Thanks again for helping us improve kics! 🥳

@cx-laura-rodrigues
cx-laura-rodrigues requested a review from a team September 9, 2026 15:49
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

⚠️ Potential secret(s) detected (unverified)

@cx-laura-rodrigues — TruffleHog found 1 potential secret(s) in this PR (0 verified, 1 unverified).

Secret Type Status Commit File Path View
Box ⚠️ unverified d610057226 .github/scripts/report/e2e-report 🔎 View secret

🛠 Guidelines to remediate hardcoded secrets

To avoid such incidents in the future consider:

  • Following the best practices for managing and storing secrets, including API keys and other credentials.
  • Re-scan after cleanup before merging.

⚠️ These are unverified matches and do not block the merge — please review and confirm they are not real secrets.

Comment thread pkg/analyzer/analyzer.go Outdated
cx-laura-rodrigues and others added 2 commits September 11, 2026 19:31
Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>

@cx-artur-ribeiro cx-artur-ribeiro left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@cx-alon-rosenhek
cx-alon-rosenhek merged commit 99a15da into master Sep 16, 2026
35 of 41 checks passed
@cx-alon-rosenhek
cx-alon-rosenhek deleted the AST-170544 branch September 16, 2026 11:00
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
kics 2.2.0

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre>## What's Changed
* docs(release): update queries catalog, index and dockerfile for upcoming release by @cx-artur-ribeiro in Checkmarx/kics#8094
* fix(query): added missing case to "Last User is Root" Dockerfile query. by @cx-andre-pereira in Checkmarx/kics#8095
* feat(queries): new queries to check if synapse workspace managed virtual network is enabled by @cx-ricardo-jesus in Checkmarx/kics#8097
* refactor(descriptions): remove pkg/descriptions and related CLI flag by @cx-ricardo-jesus in Checkmarx/kics#8092
* CISO-1264 - Update GitHub Actions runner labels by @cx-jonathan-hartman in Checkmarx/kics#8093
* fix(query): Fix for Missing Backslash Support on Copy_With_More_Than_Two_Arguments_Not_Ending_With_Slash query by @cx-andre-pereira in Checkmarx/kics#8099
* fix(actions): refactor gh actions to fix CI by @cx-artur-ribeiro in Checkmarx/kics#8098
* fix(query): change to keyExpectedValue on ARM 'default_azure_storage_account_network_access_is_too_permissive' query by @cx-andre-pereira in Checkmarx/kics#8101
* update(version): rename VERSION build-arg to ENGINE_VERSION by @cx-artur-ribeiro in Checkmarx/kics#8102
* fix(query): correct keyExpectedValue and keyActualValue in redshift_not_encrypted by @cx-ricardo-jesus in Checkmarx/kics#8105
* fix(analyzer): bound file analysis workers by @omribz156 in Checkmarx/kics#8058
* fix(actions): remove outdated actions and update documentation accordingly by @cx-artur-ribeiro in Checkmarx/kics#8110
* fix(action): remove concurrent group from run projects github action by @cx-artur-ribeiro in Checkmarx/kics#8111
* fix(test): normalize timestamp comparison in TestInitCycloneDxReport by @cx-artur-ribeiro in Checkmarx/kics#8113
* fix(actions): fix security vulnerabilities and update ci with new enforced rules by @cx-artur-ribeiro in Checkmarx/kics#8118
* fix(release): gate kics release workflows behind release environment by @cx-lior-poterman in Checkmarx/kics#8108
* fix(validator): update queries validator for cwe and risk score fields by @cx-artur-ribeiro in Checkmarx/kics#8028
* fix(version): new available version with additional v prefix by @cx-artur-ribeiro in Checkmarx/kics#8119
* fix(analyzer): improvement to dockerfile scanning by @cx-andre-pereira in Checkmarx/kics#8114
* chore(release): removed unused goreleaser configuration files by @cx-ricardo-jesus in Checkmarx/kics#8122
* fix(filesystem): skip cache files by extension by @cx-laura-rodrigues in Checkmarx/kics#8112
* fix(query): changed all dockerfile queries for case insensitive support of dockerfile commands by @cx-andre-pereira in Checkmarx/kics#8115
* docs(release): update queries catalog, index and dockerfile for 2.2.0 by @cx-artur-ribeiro in Checkmarx/kics#8126

## New Contributors
* @cx-jonathan-hartman made their first contribution in Checkmarx/kics#8093
* @omribz156 made their first contribution in Checkmarx/kics#8058
* @cx-lior-poterman made their first contribution in Checkmarx/kics#8108

**Full Changelog**: https://github.com/Checkmarx/kics/compare/v2.1.21...v2.2.0</pre>
  <p>View the full release notes at <a href="https://github.com/Checkmarx/kics/releases/tag/v2.2.0">https://github.com/Checkmarx/kics/releases/tag/v2.2.0</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!20473
cx-andre-pereira pushed a commit that referenced this pull request Sep 29, 2026
* fix(filesystem): skip cache files by extension

* fix: improvement to regex used for docker compose detection

* Update pkg/analyzer/analyzer.go

Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>

* fix: lint

---------

Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
cx-andre-pereira pushed a commit that referenced this pull request Sep 29, 2026
* fix(filesystem): skip cache files by extension

* fix: improvement to regex used for docker compose detection

* Update pkg/analyzer/analyzer.go

Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>

* fix: lint

---------

Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants