31 lines
868 B
Python
31 lines
868 B
Python
from __future__ import annotations
|
|
|
|
import argparse
|
|
from pathlib import Path
|
|
|
|
|
|
def main() -> int:
|
|
parser = argparse.ArgumentParser(
|
|
description="Fail when a secret canary appears in output files."
|
|
)
|
|
parser.add_argument("--canary", action="append", default=[])
|
|
parser.add_argument("paths", nargs="+")
|
|
args = parser.parse_args()
|
|
findings: list[str] = []
|
|
for raw_path in args.paths:
|
|
path = Path(raw_path)
|
|
if not path.is_file():
|
|
continue
|
|
text = path.read_text(encoding="utf-8", errors="replace")
|
|
if any(canary and canary in text for canary in args.canary):
|
|
findings.append(str(path))
|
|
if findings:
|
|
print("secret canary found: " + ", ".join(findings))
|
|
return 1
|
|
print("leakage scan: OK")
|
|
return 0
|
|
|
|
|
|
if __name__ == "__main__":
|
|
raise SystemExit(main())
|