fix(sdk): align secret scan source line indexing (#12141)

Co-authored-by: jbchief-dev <285331266+jbchief-dev@users.noreply.github.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
This commit is contained in:
jbchief-dev
2026-07-30 12:44:20 +02:00
committed by GitHub
co-authored by jbchief-dev Daniel Barranquero
parent 5c4b0ba1fe
commit b7281a5221
3 changed files with 22 additions and 1 deletions
@@ -0,0 +1 @@
Secret ignore patterns now use Kingfisher-compatible LF line indexing for scanned content containing ASCII control characters
+4 -1
View File
@@ -232,7 +232,10 @@ def _scan_batch_chunk(
encoding=encoding_format_utf_8,
errors="replace",
) as f:
source_lines_cache[file_name] = f.read().splitlines()
# Kingfisher reports LF-delimited line numbers. Unlike
# splitlines(), this does not treat ASCII control characters
# such as FS, GS, and RS as additional line boundaries.
source_lines_cache[file_name] = f.read().split("\n")
return source_lines_cache[file_name]
for entry in kingfisher_output.get("findings", []):
+17
View File
@@ -227,6 +227,23 @@ class Test_detect_secrets_scan_batch:
)
assert results == {}
@pytest.mark.parametrize("separator", ["\x1c", "\x1d", "\x1e"])
def test_batch_excluded_secrets_uses_lf_line_numbers(self, separator):
payload = (
f'const characterTable = "prefix{separator}suffix";\n'
'DB_ALLOW_EMPTY_PASSWORD = "Tr0ub4dor3xKq9vLmZ"'
)
with patch(
"prowler.lib.utils.utils.subprocess.run",
side_effect=_fake_kingfisher_run_with_findings([(0, 2)]),
):
results = detect_secrets_scan_batch(
{"a": payload},
excluded_secrets=[".*ALLOW_EMPTY_PASSWORD.*"],
)
assert results == {}
def test_batch_chunking_maps_all_keys(self):
payloads = {f"k{i}": f'password = "S3cr3tV4lu3xy{i}z"' for i in range(5)}
results = detect_secrets_scan_batch(payloads, chunk_size=2)