Support for XML secrets in Keyword plugin #447
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This Pull Request introduces some regex in the KeywordDetector plugin to detect secrets in XML files. The are a lot of situations where a secret can be hardcoded in a XML file, I think that this regexes will detect secrets in the most of them.
I know that in other Pull Request, we talked with @domanchi about create a XML transformer to perform this secrets detection, but I think that it will be more complex than YAML transformer and we have to analyze what is the better approach to implement it, to get the best result as possible. We will keep it in mind for future optimizations, but now I think that this standard regexes in the Keyword plugin could achieve a good performance.
I hope you will like it!