Releases: gitleaks/gitleaks
Releases Β· gitleaks/gitleaks
v8.19.2
v8.19.1
v8.19.0
Changelog
- 44ad62e Deprecate
detect
andprotect
. Addgit
,dir
,stdin
(#1504) HEY THIS IS AN IMPORTANT CHANGE. If it breaks some stuff... sorry, I'll fix it asap, just open an issue and make sure to ping me. The change is meant to be backwards compatible. - e93a7c0 Update Harness rules to add _ and - in the account ID part. (#1503)
- 4e43d11 chore: fix gl workflow error (#1487)
- bd81872 Make config generation utils public (#1480)
- 3be7faa Update Hashicorp Vault token pattern (#1483)
- 1aae66d feat(config): update rule validation (#1466)
- 6dfcf5e Update .gitleaksignore
- f361c5e fix(detect): handle EOF with bytes (#1472)
- 8a1ca9e Added poetry.lock to default allowlist paths (#1474)
- 525c4b4 refactor(sarif): remove |name| and change |shortDescription| (#1473)
- c0fda43 Use rule id for config validation error (#1463)
- d3c4b90 Use first non-empty group if
secretGroup
isn't set (#1459) - b4009bf chore: remove unnecessary capture groups (#1460)
- 80bd177 Return non-0 exit code from
DetectGit
(#1461) - 0334ec1 add gradle verification-metadata.xml to global allowlist (#1446)
- c1345e1 feat(openshift): add user token (#1449)
- 7697b3e (feat): Adding secret detection rule for Kubernetes secrets (#1454)
- 26f3469 add version to default
- bc979de Add go.work and go.work.sum to global allowlist (#1353)
- b899915 Add harness PAT and SAT rules (#1406)
- 4c5195b Update README.md
v8.18.4
Changelog
- 02808f4 Limit hashicorp-tf-password to .tf/.hcl files (#1420)
- 07e1c30 rm print
- db63fc1 reduce telegram... todo url and xml for later
- 9a4538c coderabbit.ai <3
- fe94ef9 Add NewRelic insert key detection (#1417)
- bb4424d Improved Telegram bot token rule regex and added more test cases (#1404)
- 575e923 Add intra42 client secret (#1408)
Shout out to @coderabbit for their sponsorship!
v8.18.3
Changelog
- 39947b0 extend FB access token discovery (#1407)
- 79cac73 tests: scalingo validation consistent test (#1359)
- 247f423 add real (test) standard and restricted keys (#1375)
- 821b232 Add Cloudflare API and Origin CA keys (#1374)
- 57ac4b3 Update "contributing guidelines" link (#1390)
- db69e82 add update token from square (#1370)
- 4b54328 feat: facebook secret, access token, and page access token rules (#1372)
- 979f213 update mailchimp with new tokens (#1376)
- 59c0cc7 Append ordered rules when extending (#1304)
- 6c52f87 fix: age rule id with dashes (#1349)
- 247a5e7 patching golang.org/x/text for CVE-2021-38561 and CVE-2022-32149 (#1342)
- 8d23afd Use latest base images. (#1334)
v8.18.2
Changelog
- ac4b514 removed gitleaks user from Dockerfile (#1313)
- 76c9e31 Remove IAM identifiers for non-credential resources in the aws-access-token rule (#1307)
- afe046b Update stripe rule to not alert on publishable keys (#1320)
- 8b8920d --max-target-megabytes flag now supported for --no-git flag as well (#1330)
- a59289c add pre-commit hook gitleaks-system (#1225)
- 870194b fix errors when using protect and an external git diff tool (#1318)
- 179c607 rename filesystem to directory (#1317)
- 8de8938 Enhance Secret Descriptions (#1300)
- ca7aa14 Small refactor
detect
andsources
(#1297) - 01e60c8 chore(config): refactor to go generate; simplify configRules init (#1295)
- 54f5f04 forgot symlinks
- 221d5c4 pretty apparent 'protect' and 'detect' should be merged into one command (#1294)
- 128b50f style: sort the stopwords (#1289)
v8.18.1
Changelog
- dab7d02 dont crash on 100gb files pls (#1292)
- e63b657 remove secretgroup from default config (#1288)
- 20fcf50 feat: Hashicorp Terraform fields for password (#1237)
- b496677 perf: avoid allocations with
(*regexp.Regexp).MatchString
(#1283) - a3ab4e8 refactor: more explicit rules (#1280)
- bd9a25a bugfix: reduce false positives for stripe tokens by using word boundaries in regex (#1278)
- 6d0d8b5 add Infracost API rule (#1273)
- 2959fc0 refactor: simplify test asserts (#1271)
- d37b38f Update Makefile
- 14b1ca9 refactor: change detect tests to t.Fatal instead of log.Fatal (#1270)
- d9f86d6 feat(rules): Add detection for Scalingo API Token (#1262)
- ed34259 feat(jwt): detect base64-encoded tokens (#1256)
- 0d5e46f feat: add --ignore-gitleaks-allow cmd flag (#1260)
- a82ac29 switch out libs (#1259)
- 0b84afa fix: no-color option should also affect zerolog output (#1242)
- 8976539 Fixed lineEnd indexing if the match is the whole line (#1223)
- 30c6117 feat: Add optional redaction value, default 100 (#1229)
- e9135cf fix(jwt): longer segment lengths (#1214)
- f65f915 Added yarn.lock file to default allowlist paths (#1258)
- abfd0f3 Update README.md
- 18283bb feat(rules): make case insensitivity optional (#1215)
- 9fb36b2 feat(rules): detect Hugging Face access tokens (#1204)
- db4bc0f Resolve #1170 - Enable selection of a single rule (#1183)
- 3cbcda2 Update authress.go to include alternate form account dash (-) (#1224)
- 46c6272 refactor: remove unnecessary removing temp files in tests (#1255)
- 963a697 refactor: use os.ReadFile instead of os.Open + io.ReadAll (#1254)
- 163ec21 fix(sumologic): improve patterns (#1218)
v8.18.0
What's Changed
- Fix inconsistent generated values in config by @rgmz in #1200
- feat: add JFrog API and Identity keys by @baruchiro in #1233
- Add entropy check to plaid client/secret ID rules by @mortenson in #1213
- Update config template logic by @rgmz in #1201
- Include entropy in Plaid rule file by @rgmz in #1252
- refactor: fix #722 properly by @L11r in #1250
New Contributors
- @baruchiro made their first contribution in #1233
- @mortenson made their first contribution in #1213
- @L11r made their first contribution in #1250
Full Changelog: v8.17.0...v8.18.0
v8.17.0
What's Changed
- Add
REDACTED
to stopwords forgeneric-api-key
rule by @9999years in #1188 - Add detection for Snyk tokens by @wayne-snyk in #1190
- Add makefile variable detections by @wayne-snyk in #1191
- chore: update deps to fix solaris #1158 by @gaige in #1159
- Add junit report format by @maltemorgenstern in #920
- Ignore all comits when
.gitleaksignore
fingerprint lacks SHA by @rgmz in #1156 - Improved global exclusion list by @sergiomarotco in #1193
- Add detection for OpenAI API keys by @becojo in #1148
- Add warning for quoted
--log-opts
values by @rgmz in #1160 - Fixed docker run command in README.md by @IanMoroney in #1194
- add tags support for csv and sarif formats by @eyalatox in #1176
- Update Slack token regexes by @rgmz in #1161
New Contributors
- @9999years made their first contribution in #1188
- @wayne-snyk made their first contribution in #1190
- @gaige made their first contribution in #1159
- @IanMoroney made their first contribution in #1194
- @eyalatox made their first contribution in #1176
- @dvasdekis made their first contribution in #1079
Full Changelog: v8.16.4...v8.17.0
v8.16.4
Changelog
- 6f75511 Added option to specify .gitleaksignore path (#1179) @pacorreia
- 190ac97 Fix closing file in writeJson and writeSarif (#1187) @alexandear
- 6dbb0c5 Simplify tests by using T.TempDir (#1186) @alexandear
- 6705461 Fix typos in *.md, comments and logs (#1185) @alexandear
- 9869eab Update README.md
- 16f1ec0 Update bug_report.md
- 8d80a5a Adding discord channel to readme
- 146f69e π fix(sarif): update report to pass validator (#1167) @DariuszPorowski