
Escáner de secretos multi-fuente que detecta claves API, contraseñas e información de identificación personal (PII) en repositorios Git, buckets S3, sistemas de archivos, Confluence, JIRA, Slack y Google Docs mediante expresiones regulares y análisis de entropía.
Rusty Hog es un escáner de secretos construido en Rust para rendimiento, y basado en TruffleHog que está escrito en Python. Rusty Hog proporciona los siguientes binarios:
Este proyecto proporciona un conjunto de escáneres que utilizan expresiones regulares para intentar detectar la presencia de información sensible, como claves de API, contraseñas e información personal. Incluye un conjunto de expresiones regulares por defecto, pero también acepta un objeto JSON con tus expresiones regulares personalizadas.
Descarga y descomprime el último ZIP
en la pestaña de versiones. Luego, ejecuta cada binario con -h para ver el uso.```shell script
wget https://github.com/newrelic/rusty-hog/releases/download/v1.0.11/rustyhogs-darwin-choctaw_hog-1.0.11.zip
unzip rustyhogs-darwin-choctaw_hog-1.0.11.zip
darwin_releases/choctaw_hog -h
## Cómo ejecutar usando DockerHub
Las imágenes Docker de Rusty Hog se pueden encontrar en la página personal de DockerHub del autor [aquí](https://hub.docker.com/u/wetfeet2000)
Se crea una imagen Docker para cada Hog y para cada versión. Así que para usar choctaw_hog, ejecutarías los siguientes comandos:```shell script
docker pull wetfeet2000/choctaw_hog:1.0.10
docker run -it --rm wetfeet2000/choctaw_hog:1.0.10 --help
cargo build --release. Los binarios se encuentran en target/release.cargo doc --no-deps --open.cargo test.## Cómo compilar en Windows
Necesitarás compilar binarios estáticos de OpenSSL e indicarle a Rust/Cargo dónde encontrarlos:```
mkdir \Tools
cd \Tools
git clone https://github.com/Microsoft/vcpkg.git
cd vcpkg
.\bootstrap-vcpkg.bat
.\vcpkg.exe install openssl:x64-windows-static
$env:OPENSSL_DIR = 'C:\Tools\vcpkg\installed\x64-windows-static'
$env:OPENSSL_STATIC = 'Yes'
[System.Environment]::SetEnvironmentVariable('OPENSSL_DIR', $env:OPENSSL_DIR, [System.EnvironmentVariableTarget]::User)
[System.Environment]::SetEnvironmentVariable('OPENSSL_STATIC', $env:OPENSSL_STATIC, [System.EnvironmentVariableTarget]::User)
Ahora puedes seguir las instrucciones principales de compilación enumeradas anteriormente.
Usa Homebrew para obtener las dependencias:``` brew install rpm2cpio FiloSottile/musl-cross/musl-cross
Luego ejecuta `./build_lambda_macos.sh`.
El script de compilación compilará contra OpenSSL 3.0.12. Usa `export OPENSSL_BUILD_VER=3.0.12` para sobrescribir.
El script de compilación compilará contra los encabezados del kernel de Amazon Linux proporcionados por su RPM; `export AMAZON_KERNEL_HEADERS_RPM_URL=...` para sobrescribir de dónde se descarga el RPM. (No hay nada que impida que se use un RPM de linux-headers de una distribución diferente, solo necesitamos los linux-headers para compilar openssl para Linux)
El script de compilación creará un directorio build-deps en la raíz de tu fuente actual. Puedes eliminar este directorio de forma segura con `rm -rf`, pero se recreará en la próxima ejecución del script de compilación. También realizará varias comprobaciones de coherencia para asegurarse de que la compilación funcione y, si fallan, podría pedirte que elimines ese directorio con `rm -rf` de todos modos para intentarlo de nuevo.
### Linux
Asegúrate de que `cross` esté instalado (`cargo install cross`), luego simplemente ejecuta `./build_lambda.sh`.
# Comandos
## Uso de Anakamali Hog (GDoc Scanner)```
USAGE:
ankamali_hog [FLAGS] [OPTIONS] <GDRIVEID>
FLAGS:
--caseinsensitive Sets the case insensitive flag for all regexes
--entropy Enables entropy scanning
--oauthsecret Path to an OAuth secret file (JSON) ./clientsecret.json by default
--oauthtoken Path to an OAuth token storage file ./temp_token by default
--prettyprint Outputs the JSON in human readable format
-v, --verbose Sets the level of debugging information
-h, --help Prints help information
-V, --version Prints version information
OPTIONS:
-a, --allowlist <ALLOWLIST> Sets a custom allowlist JSON file
--default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (0.6 by default)
-o, --outputfile <OUTPUT> Sets the path to write the scanner results to (stdout by default)
--regex <REGEX> Sets a custom regex JSON file
ARGS:
<GDRIVEID> The ID of the Google drive file you want to scan
USAGE: berkshire_hog [FLAGS] [OPTIONS]
FLAGS: --caseinsensitive Sets the case insensitive flag for all regexes --entropy Enables entropy scanning --prettyprint Outputs the JSON in human readable format -r, --recursive Recursively scans files under the prefix -v, --verbose Sets the level of debugging information -h, --help Prints help information -V, --version Prints version information
OPTIONS: -a, --allowlist Sets a custom allowlist JSON file --default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (0.6 by default) -o, --outputfile Sets the path to write the scanner results to (stdout by default)
--profile <PROFILE> When using a configuration file, enables a non-default profile
--regex <REGEX> Sets a custom regex JSON file
ARGS: The location of a S3 bucket and optional prefix or filename to scan. This must be written in the form s3://mybucket[/prefix_or_file] Sets the region of the S3 bucket to scan
## Uso de Berkshire Hog (Escáner S3 - Lambda)
Berkshire Hog está diseñado actualmente para ser utilizado como una función Lambda. Este es el flujo de datos básico:
<pre>
┌───────────┐ ┌───────┐ ┌────────────────┐ ┌────────────┐
│ S3 bucket │ ┌────────┐ │ │ │ Berkshire Hog │ │ S3 bucket │
│ (input) ─┼─┤S3 event├──▶│ SQS │────▶│ (Lambda) │────▶│ (output) │
│ │ └────────┘ │ │ │ │ │ │
└───────────┘ └───────┘ └────────────────┘ └────────────┘
</pre>
Para ejecutar Berkshire Hog de esta manera, configure lo siguiente:
1) Configure el bucket de entrada para enviar un "evento" a SQS por cada evento PUSH/PUT.
2) Configure el tema SQS para aceptar eventos de S3, incluidos los permisos IAM.
3) Ejecute Berkshire Hog con acceso IAM a SQS y S3.
## Uso de Choctaw Hog (Escáner Git)```
USAGE:
choctaw_hog [FLAGS] [OPTIONS] <GITPATH>
FLAGS:
--caseinsensitive Sets the case insensitive flag for all regexes
--entropy Enables entropy scanning
--prettyprint Outputs the JSON in human readable format
-v, --verbose Sets the level of debugging information
-h, --help Prints help information
-V, --version Prints version information
OPTIONS:
--default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (4.5 by default)
--httpspass <HTTPSPASS> Takes a password for HTTPS-based authentication
--httpsuser <HTTPSUSER> Takes a username for HTTPS-based authentication
-o, --outputfile <OUTPUT> Sets the path to write the scanner results to (stdout by default)
--recent_days <RECENTDAYS> Filters commits to the last number of days (branch agnostic)
-r, --regex <REGEX> Sets a custom regex JSON file
--since_commit <SINCECOMMIT> Filters commits based on date committed (branch agnostic)
--sshkeypath <SSHKEYPATH> Takes a path to a private SSH key for git authentication, defaults to ssh-agent
--sshkeyphrase <SSHKEYPHRASE> Takes a passphrase to a private SSH key for git authentication, defaults to none
--until_commit <UNTILCOMMIT> Filters commits based on date committed (branch agnostic)
-a, --allowlist <ALLOWLIST> Sets a custom ALLOWLIST JSON file
ARGS:
<GITPATH> Sets the path (or URL) of the Git repo to scan. SSH links must include username (git@)
USAGE: duroc_hog [FLAGS] [OPTIONS]
FLAGS: --caseinsensitive Sets the case insensitive flag for all regexes --entropy Enables entropy scanning --norecursive Disable recursive scanning of all subdirectories underneath the supplied path --prettyprint Outputs the JSON in human readable format -z, --unzip Recursively scans archives (ZIP and TAR) in memory (dangerous) -v, --verbose Sets the level of debugging information -h, --help Prints help information -V, --version Prints version information
OPTIONS: -a, --allowlist Sets a custom allowlist JSON file --default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (0.6 by default) -o, --outputfile Sets the path to write the scanner results to (stdout by default) -r, --regex Sets a custom regex JSON file
ARGS: Sets the path of the directory or file to scan.
## Uso de Essex Hog (escáner de Confluence)```
USAGE:
essex_hog [FLAGS] [OPTIONS] <PAGEID> <URL>
FLAGS:
--caseinsensitive Sets the case insensitive flag for all regexes
--entropy Enables entropy scanning
--prettyprint Outputs the JSON in human readable format
-v, --verbose Sets the level of debugging information
-h, --help Prints help information
-V, --version Prints version information
OPTIONS:
-a, --allowlist <ALLOWLIST> Sets a custom allowlist JSON file
--authtoken <BEARERTOKEN> Confluence basic auth bearer token (instead of user & pass)
--default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (0.6 by default)
-o, --outputfile <OUTPUT> Sets the path to write the scanner results to (stdout by default)
--password <PASSWORD> Confluence password (crafts basic auth header)
--regex <REGEX> Sets a custom regex JSON file
--username <USERNAME> Confluence username (crafts basic auth header)
ARGS:
<PAGEID> The ID (e.g. 1234) of the confluence page you want to scan
<URL> Base URL of Confluence instance (e.g. https://newrelic.atlassian.net/)
Jira secret scanner in Rust.
USAGE: gottingen_hog [FLAGS] [OPTIONS]
FLAGS: --caseinsensitive Sets the case insensitive flag for all regexes --entropy Enables entropy scanning --prettyprint Outputs the JSON in human readable format -v, --verbose Sets the level of debugging information -h, --help Prints help information -V, --version Prints version information
OPTIONS: -a, --allowlist Sets a custom allowlist JSON file --authtoken Jira basic auth bearer token (instead of user & pass) --default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (0.6 by default) --url Base URL of JIRA instance (e.g. https://jira.atlassian.net/) -o, --outputfile Sets the path to write the scanner results to (stdout by default) --password Jira password (crafts basic auth header) --regex Sets a custom regex JSON file --username Jira username (crafts basic auth header)
ARGS: The ID (e.g. PROJECT-123) of the Jira issue you want to scan
## Uso de Hante Hog (SLACK scanner)```
Slack secret scanner in Rust.
USAGE:
hante_hog [FLAGS] [OPTIONS] --authtoken <BEARERTOKEN> --channelid <CHANNELID> --url <SLACKURL>
FLAGS:
--caseinsensitive Sets the case insensitive flag for all regexes
--entropy Enables entropy scanning
--prettyprint Outputs the JSON in human readable format
-v, --verbose Sets the level of debugging information
-h, --help Prints help information
-V, --version Prints version information
OPTIONS:
-a, --allowlist <ALLOWLIST> Sets a custom allowlist JSON file
--authtoken <BEARERTOKEN> Slack basic auth bearer token
--channelid <CHANNELID>
The ID (e.g. C12345) of the Slack channel you want to scan
--default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (0.6 by default)
--latest <LATEST> End of time range of messages to include in search
--oldest <OLDEST> Start of time range of messages to include in search
-o, --outputfile <OUTPUT>
Sets the path to write the scanner results to (stdout by default)
--regex <REGEX> Sets a custom regex JSON file
--url <SLACKURL>
Base URL of Slack Workspace (e.g. https://[WORKSPACE NAME].slack.com)
La opción de expresiones regulares en los escáneres permite a los usuarios proporcionar una ruta a su propio archivo JSON de expresiones regulares que coinciden con material sensible. Cualquier archivo proporcionado actualmente reemplazará, no añadirá, las expresiones regulares predeterminadas proporcionadas por SecretScanner. El formato esperado del archivo es un objeto json único.
Las claves deben ser nombres para el tipo de secreto que detectará cada entrada de expresión regular, ya que las claves se utilizarán para las propiedades de motivo que genera el escáner.
Cada valor debe ser una cadena que contenga una [https://docs.rs/regex/1.3.9/regex/#syntax](expresión regular válida para Rust) que debe coincidir con el tipo de secreto descrito por su clave correspondiente.
A partir de la versión 1.0.8, el motor Rusty Hog también admite objetos como valores para cada secreto. El objeto puede contener todo lo siguiente:
Cuanto mayor sea el umbral, más entropía se requiere en el secreto para considerarlo una coincidencia.
Aquí hay un ejemplo de este formato:```json { "Generic Secret": { "pattern": "(?i)secret[\s[[:punct:]]]{1,4}[0-9a-zA-Z-]{16,64}[\s[[:punct:]]]?", "entropy_filter": true, "threshold": "0.6" }, "Slack Token": { "pattern": "(xox[p|b|o|a]-[0-9]{12}-[0-9]{12}-[0-9]{12}-[a-z0-9]{32})", "entropy_filter": true, "threshold": "0.6", "keyspace": "36", "make_ascii_lowercase": true }, "Google API Key": { "pattern": "AIza[0-9A-Za-z\-]{35}", "entropy_filter": true }, "PGP private key block": "-----BEGIN PGP PRIVATE KEY BLOCK-----" }
A partir de la versión 1.0.11, el JSON de regex predeterminado actual utilizado es el siguiente:```json
{
"Slack Token": "(xox[p|b|o|a]-[0-9]{12}-[0-9]{12}-[0-9]{12}-[a-z0-9]{32})",
"RSA private key": "-----BEGIN RSA PRIVATE KEY-----",
"SSH (DSA) private key": "-----BEGIN DSA PRIVATE KEY-----",
"SSH (EC) private key": "-----BEGIN EC PRIVATE KEY-----",
"PGP private key block": "-----BEGIN PGP PRIVATE KEY BLOCK-----",
"Amazon AWS Access Key ID": "AKIA[0-9A-Z]{16}",
"Amazon MWS Auth Token": "amzn\\.mws\\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}",
"Facebook Access Token": "EAACEdEose0cBA[0-9A-Za-z]+",
"Facebook OAuth": "(?i)facebook[\\s[[:punct:]]]{1,4}[0-9a-f]{32}[\\s[[:punct:]]]?",
"GitHub": "(?i)(github|access[[:punct:]]token)[\\s[[:punct:]]]{1,4}[0-9a-zA-Z]{35,40}",
"Generic API Key": {
"pattern": "(?i)(api|access)[\\s[[:punct:]]]?key[\\s[[:punct:]]]{1,4}[0-9a-zA-Z\\-_]{16,64}[\\s[[:punct:]]]?",
"entropy_filter": true,
"threshold": "0.6",
"keyspace": "guess"
},
"Generic Account API Key": {
"pattern": "(?i)account[\\s[[:punct:]]]?api[\\s[[:punct:]]]{1,4}[0-9a-zA-Z\\-_]{16,64}[\\s[[:punct:]]]?",
"entropy_filter": true,
"threshold": "0.6",
"keyspace": "guess"
},
"Generic Secret": {
"pattern": "(?i)secret[\\s[[:punct:]]]{1,4}[0-9a-zA-Z-_]{16,64}[\\s[[:punct:]]]?",
"entropy_filter": true,
"threshold": "0.6",
"keyspace": "guess"
},
"Google API Key": "AIza[0-9A-Za-z\\-_]{35}",
"Google Cloud Platform API Key": "AIza[0-9A-Za-z\\-_]{35}",
"Google Cloud Platform OAuth": "(?i)[0-9]+-[0-9A-Za-z_]{32}\\.apps\\.googleusercontent\\.com",
"Google Drive API Key": "AIza[0-9A-Za-z\\-_]{35}",
"Google Drive OAuth": "(?i)[0-9]+-[0-9A-Za-z_]{32}\\.apps\\.googleusercontent\\.com",
"Google (GCP) Service-account": "(?i)\"type\": \"service_account\"",
"Google Gmail API Key": "AIza[0-9A-Za-z\\-_]{35}",
"Google Gmail OAuth": "(?i)[0-9]+-[0-9A-Za-z_]{32}\\.apps\\.googleusercontent\\.com",
"Google OAuth Access Token": "ya29\\.[0-9A-Za-z\\-_]+",
"Google YouTube API Key": "AIza[0-9A-Za-z\\-_]{35}",
"Google YouTube OAuth": "(?i)[0-9]+-[0-9A-Za-z_]{32}\\.apps\\.googleusercontent\\.com",
"Heroku API Key": "[h|H][e|E][r|R][o|O][k|K][u|U][\\s[[:punct:]]]{1,4}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}",
"MailChimp API Key": "[0-9a-f]{32}-us[0-9]{1,2}",
"Mailgun API Key": "(?i)key-[0-9a-zA-Z]{32}",
"Credentials in absolute URL": "(?i)((https?|ftp)://)(([a-z0-9$_\\.\\+!\\*'\\(\\),;\\?&=-]|%[0-9a-f]{2})+(:([a-z0-9$_\\.\\+!\\*'\\(\\),;\\?&=-]|%[0-9a-f]{2})+)@)((([a-z0-9]\\.|[a-z0-9][a-z0-9-]*[a-z0-9]\\.)*[a-z][a-z0-9-]*[a-z0-9]|((\\d|[1-9]\\d|1\\d{2}|2[0-4][0-9]|25[0-5])\\.){3}(\\d|[1-9]\\d|1\\d{2}|2[0-4][0-9]|25[0-5]))(:\\d+)?)(((/+([a-z0-9$_\\.\\+!\\*'\\(\\),;:@&=-]|%[0-9a-f]{2})*)*(\\?([a-z0-9$_\\.\\+!\\*'\\(\\),;:@&=-]|%[0-9a-f]{2})*)?)?)?",
"PayPal Braintree Access Token": "(?i)access_token\\$production\\$[0-9a-z]{16}\\$[0-9a-f]{32}",
"Picatic API Key": "(?i)sk_live_[0-9a-z]{32}",
"Slack Webhook": "(?i)https://hooks.slack.com/services/T[a-zA-Z0-9_]{8}/B[a-zA-Z0-9_]{8}/[a-zA-Z0-9_]{24}",
"Stripe API Key": "(?i)sk_live_[0-9a-zA-Z]{24}",
"Stripe Restricted API Key": "(?i)rk_live_[0-9a-zA-Z]{24}",
"Square Access Token": "(?i)sq0atp-[0-9A-Za-z\\-_]{22}",
"Square OAuth Secret": "(?i)sq0csp-[0-9A-Za-z\\-_]{43}",
"Twilio API Key": "SK[0-9a-fA-F]{32}",
"Twitter Access Token": "(?i)twitter[\\s[[:punct:]]]{1,4}[1-9][0-9]+-[0-9a-zA-Z]{40}",
"Twitter OAuth": "(?i)twitter[\\s[[:punct:]]]{1,4}['|\"]?[0-9a-zA-Z]{35,44}['|\"]?",
"New Relic Partner & REST API Key": "[\\s[[:punct:]]][A-Fa-f0-9]{47}[\\s[[:punct:]][[:cntrl:]]]",
"New Relic Mobile Application Token": "[\\s[[:punct:]]][A-Fa-f0-9]{42}[\\s[[:punct:]][[:cntrl:]]]",
"New Relic Synthetics Private Location": "(?i)minion_private_location_key",
"New Relic Insights Key (specific)": "(?i)insights[\\s[[:punct:]]]?(key|query|insert)[\\s[[:punct:]]]{1,4}\\b[\\w-]{32,40}\\b",
"New Relic Insights Key (vague)": "(?i)(query|insert)[\\s[[:punct:]]]?key[\\s[[:punct:]]]{1,4}b[\\w-]{32,40}\\b",
"New Relic License Key": "(?i)license[\\s[[:punct:]]]?key[\\s[[:punct:]]]{1,4}\\b[\\w-]{32,40}\\b",
"New Relic Internal API Key": "(?i)nr-internal-api-key",
"New Relic HTTP Auth Headers and API Key": "(?i)(x|newrelic|nr)-?(admin|partner|account|query|insert|api|license)-?(id|key)[\\s[[:punct:]]]{1,4}\\b[\\w-]{32,47}\\b",
"New Relic API Key Service Key (new format)": "(?i)NRAK-[A-Z0-9]{27}",
"New Relic APM License Key (new format)": "(?i)[a-f0-9]{36}NRAL",
"New Relic APM License Key (new format, region-aware)": "(?i)[a-z]{2}[0-9]{2}xx[a-f0-9]{30}NRAL",
"New Relic REST API Key (new format)": "(?i)NRRA-[a-f0-9]{42}",
"New Relic Admin API Key (new format)": "(?i)NRAA-[a-f0-9]{27}",
"New Relic Insights Insert Key (new format)": "(?i)NRII-[A-Za-z0-9-_]{32}",
"New Relic Insights Query Key (new format)": "(?i)NRIQ-[A-Za-z0-9-_]{32}",
"New Relic Synthetics Private Location Key (new format)": "(?i)NRSP-[a-z]{2}[0-9]{2}[a-f0-9]{31}",
"Email address": "(?i)\\b(?:[a-z0-9!#$%&'*+/=?^_`{|}~-]+(?:\\.[a-z0-9!#$%&'*+/=?^_`{|}~-]+)*)@[a-z0-9][a-z0-9-]+\\.(com|de|cn|net|uk|org|info|nl|eu|ru)([\\W&&[^:/]]|\\A|\\z)",
"New Relic Account IDs in URL": "(newrelic\\.com/)?accounts/\\d{1,10}/",
"Account ID": "(?i)account[\\s[[:punct:]]]?id[\\s[[:punct:]]]{1,4}\\b[\\d]{1,10}\\b",
"Salary Information": "(?i)(salary|commission|compensation|pay)([\\s[[:punct:]]](amount|target))?[\\s[[:punct:]]]{1,4}\\d+"
}
Los escáneres proporcionan una función de lista blanca. Esto permite especificar una lista de expresiones regulares para cada patrón que será ignorado por el escáner. Ahora puede proporcionar opcionalmente una lista de expresiones regulares que se evalúan también contra la ruta del archivo.
El formato para este archivo de lista blanca debe ser un único objeto json. Cada clave en la lista blanca debe coincidir con una clave en el json de expresiones regulares, y el valor puede ser una de dos cosas:
Además, puede especificar la clave <GLOBAL> que se evalúa contra todos los patrones.
La siguiente es la lista blanca predeterminada incluida en todos los escaneos:```json { "Email address": { "patterns": [ "(?i)@newrelic.com", "(?i)noreply@", "(?i)test@" ], "paths": [ "(?i)authors", "(?i)contributors", "(?i)license", "(?i)maintainers", "(?i)third_party_notices" ] }, "Credentials in absolute URL": { "patterns": [ "(?i)(https?://)?user:pass(word)?@" ] }, "New Relic API Key Service Key (new format)": { "patterns": [ "NRAK-123456789ABCDEFGHIJKLMNOPQR" ] }, "Generic API Key": { "patterns": [ "(?i)sanitizeAPIKeyForLogging" ] }, "New Relic License Key": { "patterns": [ "(?i)bootstrap_newrelic_admin_license_key", "(?i)xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx", "(?i)YOUR_NEW_RELIC_LICENSE_KEY__LICENSE", "(?i)YOUR_NEW_RELIC_APPLICATION_TOKEN" ] }, "Generic Secret": { "patterns": [ "(?i)secret:NewRelicLicenseKeySecret" ] }, "": [ "(?i)example", "(?i)fake", "(?i)replace", "(?i)deadbeef", "(?i)ABCDEFGHIJKLMNOPQRSTUVWX", "1234567890" ] }
Ten en cuenta que en estos son cadenas, no expresiones regulares, y las claves de esta lista blanca deben ser una clave en el json de regex.
Las claves distinguen entre mayúsculas y minúsculas.
# Información del proyecto
## Licencia de código abierto
Este proyecto se distribuye bajo la [licencia Apache 2](https://github.com/newrelic/rusty-hog/blob/master/LICENSE).
## Soporte
New Relic ha publicado este proyecto como código abierto. Este proyecto se proporciona TAL CUAL SIN GARANTÍA NI SOPORTE, aunque puedes reportar problemas y contribuir al proyecto aquí en GitHub.
_Por favor, no reportes problemas con este software al Soporte Técnico Global de New Relic._
## Comunidad
New Relic aloja y modera un foro en línea donde los clientes pueden interactuar con empleados de New Relic, así como con otros clientes, para obtener ayuda y compartir mejores prácticas. Como todos los proyectos oficiales de código abierto de New Relic, hay un tema de Comunidad relacionado en el Explorer's Hub de New Relic. Puedes encontrar el tema/hilos de este proyecto aquí:
https://discuss.newrelic.com/t/rusty-hog-multi-platform-secret-key-scanner/90117
## Problemas / solicitudes de mejora
Envía problemas y solicitudes de mejora en la [pestaña de Issues de este repositorio](../../issues). Por favor, busca y revisa los issues abiertos existentes antes de enviar uno nuevo.
## Contribuciones
Las contribuciones son bienvenidas (y si envías una solicitud de mejora, espera ser invitado a contribuirla tú mismo). Por favor, revisa nuestra [Guía para Contribuidores](https://github.com/newrelic/rusty-hog/blob/master/CONTRIBUTING.md).
Ten en cuenta que cuando envíes tu pull request, deberás firmar el CLA mediante el clic usando CLA-Assistant. Si deseas ejecutar nuestro CLA corporativo, o si tienes alguna pregunta, envíanos un correo electrónico a [email protected].
## Hoja de ruta de funcionalidades
- 1.1: Funcionalidades empresariales
- [ ] Soporte de archivos de configuración (en lugar de argumentos de línea de comandos)
- [ ] Soporte de variables de entorno en lugar de argumentos CLI
- [ ] Multihilo
- [ ] Mejor detección de contexto y filtrado de falsos positivos (GitHound, machine learning)
- [ ] Usar Rusoto en lugar de s3-rust
- [x] Añadir escáner JIRA
- [x] Añadir escáner de sistema de archivos y archivos
- [ ] ¿Usar características de Rust para reducir dependencias de compilación?
- 1.2: Integración con scripts más grandes e interfaces de usuario
- [ ] Soporte de API de Github para gestión de organizaciones más grandes
- [ ] Escanear todos los repositorios de una lista de usuarios
- [x] Escanear todos los repositorios de una organización
- [ ] Generar un informe web o una interfaz web. Soporte de generación de "estado guardado" desde la interfaz de usuario.
- [ ] Modelo agente/gestor
- [ ] Proceso de planificación (bloqueado por el soporte de estado guardado)
## ¿Qué significa el nombre?
TruffleHog es considerado el estándar de facto / el escáner de secretos original. He estado
creando un conjunto de herramientas de escaneo de secretos para varias plataformas basadas en TruffleHog
y necesitaba un esquema de nombres, así que empecé desde la parte superior de la
[lista de razas de cerdos](https://en.wikipedia.org/wiki/List_of_pig_breeds) de Wikipedia.
Por lo tanto, cada nombre de herramienta es una raza de cerdo que comienza con la letra "A" y va subiendo.