Commit graph

1,109 commits

Author SHA1 Message Date
Mick Grove
32be18bef0 updated alibaba rule 2026-02-01 22:32:00 -08:00
Mick Grove
92ca07739a updated alibaba rule 2026-02-01 22:31:52 -08:00
Mick Grove
52f71c4462 updated changelog 2026-01-31 23:14:06 -08:00
Mick Grove
4fd0b74d7d updated changelog 2026-01-31 23:08:30 -08:00
Mick Grove
c40226e939 added revoke command in output for validated credentials. Exposed in the html findings viewer as well 2026-01-31 22:58:53 -08:00
Mick Grove
a5d9dae9b3 added revoke command in output for validated credentials. Exposed in the html findings viewer as well 2026-01-31 22:52:57 -08:00
Mick Grove
9be5a04603 sync with main 2026-01-31 22:32:57 -08:00
Mick Grove
a31885e6f2 sync with main 2026-01-31 22:31:56 -08:00
Mick Grove
181df458ba Merge main into development
- Added mercury.yml and neon.yml rules from main
- Merged Docker Hub Organization Access Token rule from main into updated dockerhub.yml
- Resolved file location conflicts due to rules directory restructuring
2026-01-31 21:57:57 -08:00
Mick Grove
8491b03ff0 dockerhub rule update and docs update 2026-01-31 21:54:08 -08:00
Mick Grove
e1306ea55f
Merge pull request #207 from bored-engineer/patch-19
fix(age): reduce allowed characters to bech32 alphabet
2026-01-30 23:01:00 -08:00
Mick Grove
4d90cea6e3
Merge pull request #200 from bored-engineer/patch-11
fix(discord): improve kingfisher.discord.1 regex
2026-01-30 22:14:29 -08:00
Mick Grove
3730222e9f
Merge pull request #201 from bored-engineer/patch-14
feat(dockerhub): add Organization Access Token regex (kingfisher.dockerhub.2), improve PAT regex (kingfisher.dockerhub.1)
2026-01-30 22:07:44 -08:00
Mick Grove
d148f53ca1
Merge pull request #197 from bored-engineer/patch-6
feat(asana): add v2 tokens, split v1/v0 patterns
2026-01-30 22:06:14 -08:00
Mick Grove
180cb431b5
Merge pull request #198 from bored-engineer/patch-9
fix(circleci): improve kingfisher.circleci.1 regex
2026-01-30 22:04:52 -08:00
Mick Grove
d2d581c7fe
Merge pull request #199 from bored-engineer/patch-10
fix(deepseek): improve kingfisher.deepseek.1 regex
2026-01-30 22:03:55 -08:00
Mick Grove
7be3d86ea0
Merge pull request #205 from bored-engineer/patch-18
fix(planetscale): improve kingfisher.planetscale.1 regex
2026-01-30 22:03:33 -08:00
Mick Grove
00bde4abd2
Merge pull request #203 from bored-engineer/patch-17
feat(mercury): add Mercury API token rules
2026-01-30 22:03:23 -08:00
Mick Grove
ab4479506b
Merge pull request #194 from bored-engineer/patch-3
fix(airtable): improve kingfisher.airtable.1 regex
2026-01-30 22:02:54 -08:00
Mick Grove
376edbe5d1
Merge pull request #204 from bored-engineer/bored-engineer-patch-1
feat(neon): add Neon API Key rule
2026-01-30 22:02:00 -08:00
Luke Young
b81194bcd3
fix(age): reduce allowed characters to bech32 alphabet
Signed-off-by: Luke Young <bored-engineer@users.noreply.github.com>
2026-01-30 20:57:55 -08:00
Luke Young
44f732595a
Add match_all_words matcher to Asana API rules 2026-01-30 18:43:26 -08:00
Luke Young
3fa9bfe160
Update CircleCI token examples in configuration 2026-01-30 18:40:22 -08:00
Luke Young
55e331f6a4
fix(planetscale): improve kingfisher.planetscale.1 regex
Signed-off-by: Luke Young <bored-engineer@users.noreply.github.com>
2026-01-30 18:17:09 -08:00
Luke Young
678beef114
feat(neon): add Neon API Key rule 2026-01-30 18:05:59 -08:00
Luke Young
2d3279b4d3
feat(mercury): add Mercury API token rules
Signed-off-by: Luke Young <bored-engineer@users.noreply.github.com>
2026-01-30 17:45:56 -08:00
Luke Young
5b2b81ed7e
feat(dockerhub): add Organization Access Token pattern
Signed-off-by: Luke Young <bored-engineer@users.noreply.github.com>
2026-01-30 16:11:44 -08:00
Luke Young
87a92f94d9
fix(discord): improve kingfisher.discord.1 regex
Signed-off-by: Luke Young <bored-engineer@users.noreply.github.com>
2026-01-30 15:15:31 -08:00
Luke Young
97210dcaa5
fix(deepseek): improve kingfisher.deepseek.1 regex
Refactor regex pattern for DeepSeek API Key rule.

Signed-off-by: Luke Young <bored-engineer@users.noreply.github.com>
2026-01-30 15:08:24 -08:00
Luke Young
e73f2f5986
fix(circleci): improve regex
Updated the regex pattern for CircleCI API token to allow a more flexible format.

Signed-off-by: Luke Young <bored-engineer@users.noreply.github.com>
2026-01-30 14:52:37 -08:00
Luke Young
ac02fb2783
feat(asana): add v2 tokens, split v1/v0 patterns
Signed-off-by: Luke Young <bored-engineer@users.noreply.github.com>
2026-01-30 14:32:08 -08:00
Luke Young
77e3191532
fix(airtable): improve regex
Signed-off-by: Luke Young <bored-engineer@users.noreply.github.com>
2026-01-30 13:42:46 -08:00
Mick Grove
45cab25615 Added Husky precommit support and added pre-commit hook that automatically downloads and caches the appropriate binary for your platform (no Docker or manual installation required). 2026-01-30 08:33:59 -08:00
Mick Grove
5eb743711b updated changelog 2026-01-30 08:07:12 -08:00
Mick Grove
aee1050620 ensured more CLI arguments are global 2026-01-30 08:04:15 -08:00
Mick Grove
8be7941333 Added 'revoke' subcommand and support for a new optional 'revocation' structure to the rules. Supporting GitHub and Slack right now 2026-01-29 12:45:32 -08:00
Mick Grove
1c45efde3e Refactored into multiple crates. Added the 'validate' subcommand 2026-01-28 22:24:35 -08:00
Mick Grove
bd4cd4c2c2 Refactored into multiple crates. Added the 'validate' subcommand 2026-01-28 10:57:45 -08:00
Mick Grove
76be1df60c Refactored into multiple crates. Added the 'validate' subcommand 2026-01-28 10:27:24 -08:00
Mick Grove
2bf9e54ad9
Merge pull request #186 from mongodb/development v1.76.0
v1.76.0
2026-01-23 20:11:53 -08:00
Mick Grove
38a0dd9e26 Switched compression dependencies to pure-Rust bzip2/lzma implementations and pared zip features to avoid C-based codecs for bz2/xz handling. 2026-01-23 10:45:08 -08:00
Mick Grove
216fc1dbdc Switched compression dependencies to pure-Rust bzip2/lzma implementations and pared zip features to avoid C-based codecs for bz2/xz handling. 2026-01-23 09:52:11 -08:00
Mick Grove
62d22dba26 Switched compression dependencies to pure-Rust bzip2/lzma implementations and pared zip features to avoid C-based codecs for bz2/xz handling. 2026-01-22 22:32:05 -08:00
Mick Grove
bf4f825c72 Switched compression dependencies to pure-Rust bzip2/lzma implementations and pared zip features to avoid C-based codecs for bz2/xz handling. 2026-01-22 22:02:08 -08:00
Mick Grove
b4feb86f47 - Fixed validation deduplication for rules with nested unnamed captures (e.g. (?<REGEX>...(ABC|DEF)...)) to use the primary capture for grouping, ensuring each unique match triggers a separate validation request.
- Added trace-level (-vv) logging for internal validation dedup keys and grouping to aid debugging.
2026-01-21 13:13:43 -08:00
Mick Grove
1be10ee8c9
Merge pull request #184 from mongodb/development v1.75.0
v1.75.0
2026-01-16 15:30:34 -08:00
Mick Grove
049294af3d Skipped per-repository report writes when an output file is specified and emit a single aggregated report after multi-repository scans to preserve full output content in files. 2026-01-16 12:39:44 -08:00
Mick Grove
594534f69f Skipped per-repository report writes when an output file is specified and emit a single aggregated report after multi-repository scans to preserve full output content in files. 2026-01-16 11:34:13 -08:00
Mick Grove
4478ae9347 Skipped per-repository report writes when an output file is specified and emit a single aggregated report after multi-repository scans to preserve full output content in files. 2026-01-16 10:04:23 -08:00
Mick Grove
caaa31562c Skipped per-repository report writes when an output file is specified and emit a single aggregated report after multi-repository scans to preserve full output content in files. 2026-01-16 10:03:59 -08:00