Auditor
No credentials committed: cloud keys, API tokens, private keys and connection strings with passwords.
1.0.3: a connection string is judged by its PASSWORD segment, which is the credential: when that segment is a SUBSTITUTION MARKER — a template or format placeholder of any language: ${name}, $NAME, %NAME%, {name}, {{name}}, %s, %(name)s, #{name} or <name> — the line carries no value, only the place the password will come from when the program runs (a secret store, an environment variable, a format argument), so it is never a finding and the trace names the template and its marker. A literal password keeps being CRITICAL, including when the user name is a marker and the password a written-in value: the secret is the password, not the user. (1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative.))
| const PATTERNS = [ |
| { name: 'AWS access key', re: /\bAKIA[0-9A-Z]{16}\b/ }, |
| { name: 'Private key block', re: /-----BEGIN (RSA |EC |OPENSSH |DSA |PGP )?PRIVATE KEY-----/ }, |
| // a composite secret declares WHICH group is the credential |
| { name: 'Connection string with password', re: /\b(?:mongodb(?:\+srv)?|postgres(?:ql)?|mysql|redis|amqp):\/\/([^:\s/]+):([^@\s/]+)@/i, secretGroup: 2 }, |
| ]; |
| // FAIL if any line of any text file matches; each finding = { severity, path, line } |
| // ...but a credential group that is a SUBSTITUTION MARKER holds no value: it is a template, never a finding |
| const SUBSTITUTION_MARKER = /\$\{[^{}]*\}|\$[A-Za-z_]\w*|%[A-Za-z_]\w*%|\{\{?[^{}]*\}?\}|%\(?[A-Za-z_]*\)?[sdfv]|#\{[^{}]*\}|<[^<>]*>/; |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.