Documentation
¶
Overview ¶
Package generic provides general-purpose secret detectors.
Index ¶
- type APIKeyDetector
- func (d *APIKeyDetector) Description() string
- func (d *APIKeyDetector) EntropyBased() bool
- func (d *APIKeyDetector) EntropyGated(raw detector.RawFinding) bool
- func (d *APIKeyDetector) ID() string
- func (d *APIKeyDetector) Keywords() []string
- func (d *APIKeyDetector) Scan(_ context.Context, data []byte) []detector.RawFinding
- func (d *APIKeyDetector) Severity() finding.Severity
- type StructuredConfigDetector
- func (d *StructuredConfigDetector) Description() string
- func (d *StructuredConfigDetector) FallbackOnSpecializedOverlap() bool
- func (d *StructuredConfigDetector) ID() string
- func (d *StructuredConfigDetector) Keywords() []string
- func (d *StructuredConfigDetector) Scan(ctx context.Context, data []byte) []detector.RawFinding
- func (d *StructuredConfigDetector) Severity() finding.Severity
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type APIKeyDetector ¶
type APIKeyDetector struct{}
APIKeyDetector detects generic API key assignments.
func (*APIKeyDetector) Description ¶
func (d *APIKeyDetector) Description() string
func (*APIKeyDetector) EntropyBased ¶ added in v1.7.0
func (d *APIKeyDetector) EntropyBased() bool
EntropyBased marks this as a heuristic detector: it matches arbitrary high-entropy strings rather than a fixed credential format, so it opts into the engine's Shannon-entropy floor (config entropy.threshold) in addition to its own baseline filter. Structural detectors do not implement this and are never entropy-gated.
func (*APIKeyDetector) EntropyGated ¶ added in v1.8.0
func (d *APIKeyDetector) EntropyGated(raw detector.RawFinding) bool
EntropyGated reports whether one raw finding should be subject to the engine-level entropy threshold. Explicit APISIX Admin API header names are a strong structural context and are therefore not entropy-gated; real APISIX keys are commonly 32-character hex values whose Shannon entropy can be below the generic threshold. Other generic assignments retain both entropy gates.
func (*APIKeyDetector) ID ¶
func (d *APIKeyDetector) ID() string
func (*APIKeyDetector) Keywords ¶
func (d *APIKeyDetector) Keywords() []string
func (*APIKeyDetector) Scan ¶
func (d *APIKeyDetector) Scan(_ context.Context, data []byte) []detector.RawFinding
Scan searches the data for generic API key assignment patterns. Applies Shannon entropy filtering after regex matching; matches with entropy below minEntropy, or whose letter composition looks like natural-language text rather than random secret material, are skipped as unlikely to be real secrets.
func (*APIKeyDetector) Severity ¶
func (d *APIKeyDetector) Severity() finding.Severity
type StructuredConfigDetector ¶ added in v1.8.0
type StructuredConfigDetector struct{}
StructuredConfigDetector detects secrets stored in high-confidence leaf fields of JSON/JSONC, YAML, TOML, XML and dotenv configuration files. Each syntax has a bounded adapter; formats are not fed through one permissive cross-format regexp. Explicit field context can therefore detect human-style and short secrets without weakening the generic detector's false-positive gates.
func (*StructuredConfigDetector) Description ¶ added in v1.8.0
func (d *StructuredConfigDetector) Description() string
func (*StructuredConfigDetector) FallbackOnSpecializedOverlap ¶ added in v1.8.0
func (d *StructuredConfigDetector) FallbackOnSpecializedOverlap() bool
FallbackOnSpecializedOverlap marks this context detector as a fallback when a specialized detector identifies the same source value. The engine keeps the provider-specific severity, verification and remediation in that case.
func (*StructuredConfigDetector) ID ¶ added in v1.8.0
func (d *StructuredConfigDetector) ID() string
func (*StructuredConfigDetector) Keywords ¶ added in v1.8.0
func (d *StructuredConfigDetector) Keywords() []string
func (*StructuredConfigDetector) Scan ¶ added in v1.8.0
func (d *StructuredConfigDetector) Scan(ctx context.Context, data []byte) []detector.RawFinding
func (*StructuredConfigDetector) Severity ¶ added in v1.8.0
func (d *StructuredConfigDetector) Severity() finding.Severity