Compare commits
2 Commits
5c72b0b3fc
..
main
| Author | SHA1 | Date | |
|---|---|---|---|
| ec5e992beb | |||
| f057648ce2 |
+2
-2
@@ -12,14 +12,14 @@ regexes = [
|
|||||||
[[rules]]
|
[[rules]]
|
||||||
id = "docker-env-password"
|
id = "docker-env-password"
|
||||||
description = "Hardcoded password in docker-compose environment"
|
description = "Hardcoded password in docker-compose environment"
|
||||||
regex = '''(?i)(PASSWORD|PASS|PWD)\s*[:=]\s*['"]?([^$'{"][^\s'"]{5,})['"]?'''
|
regex = '''(?im)^\s*-?\s*[A-Z0-9_]*(PASSWORD|PASS|PWD)\s*[:=]\s*['"]?([A-Za-z0-9][A-Za-z0-9!@#%^&+=.,_~/-]{7,})['"]?\s*(?:#.*)?$'''
|
||||||
secretGroup = 2
|
secretGroup = 2
|
||||||
tags = ["docker", "compose", "password", "env"]
|
tags = ["docker", "compose", "password", "env"]
|
||||||
|
|
||||||
[[rules]]
|
[[rules]]
|
||||||
id = "docker-env-secret"
|
id = "docker-env-secret"
|
||||||
description = "Hardcoded secret, token, or API key in docker-compose environment"
|
description = "Hardcoded secret, token, or API key in docker-compose environment"
|
||||||
regex = '''(?i)(SECRET|TOKEN|API[_-]?KEY)\s*[:=]\s*['"]?([^$'{"][A-Za-z0-9_\-]{15,})['"]?'''
|
regex = '''(?im)^\s*-?\s*[A-Z0-9_]*(SECRET|TOKEN|API[_-]?KEY)\s*[:=]\s*['"]?([A-Za-z0-9][A-Za-z0-9_\-]{19,})['"]?\s*(?:#.*)?$'''
|
||||||
secretGroup = 2
|
secretGroup = 2
|
||||||
tags = ["docker", "compose", "secret", "env"]
|
tags = ["docker", "compose", "secret", "env"]
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user