feat(v2): add secure control plane
This commit is contained in:
@@ -0,0 +1,30 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
from pathlib import Path
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(
|
||||
description="Fail when a secret canary appears in output files."
|
||||
)
|
||||
parser.add_argument("--canary", action="append", default=[])
|
||||
parser.add_argument("paths", nargs="+")
|
||||
args = parser.parse_args()
|
||||
findings: list[str] = []
|
||||
for raw_path in args.paths:
|
||||
path = Path(raw_path)
|
||||
if not path.is_file():
|
||||
continue
|
||||
text = path.read_text(encoding="utf-8", errors="replace")
|
||||
if any(canary and canary in text for canary in args.canary):
|
||||
findings.append(str(path))
|
||||
if findings:
|
||||
print("secret canary found: " + ", ".join(findings))
|
||||
return 1
|
||||
print("leakage scan: OK")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
Reference in New Issue
Block a user