代码拉取完成,页面将自动刷新
同步操作将从 jiujiangxueyuan/DevOps-Bash-tools 强制同步,此操作会覆盖自 Fork 仓库以来所做的任何修改,且无法恢复!!!
确定后同步将在后台操作,完成时将刷新页面,请耐心等待。
#!/usr/bin/env bash
# shellcheck disable=SC2230
# vim:ts=4:sts=4:sw=4:et
#
# Author: Hari Sekhon
# Date: 2019-10-18 13:57:12 +0100 (Fri, 18 Oct 2019)
#
# https://github.com/harisekhon/bash-tools
#
# License: see accompanying Hari Sekhon LICENSE file
#
# If you're using my code you're welcome to connect with me on LinkedIn and optionally send me feedback
#
# https://www.linkedin.com/in/harisekhon
#
set -euo pipefail
[ -n "${DEBUG:-}" ] && set -x
srcdir="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
# shellcheck source=lib/utils.sh
. "$srcdir/lib/utils.sh"
section "AWS Git credentials scan"
start_time="$(start_timer)"
location="${1:-.}"
if [ "$location" = . ]; then
:
elif [ -d "$location" ]; then
cd "$location"
else
cd "$(dirname "$location")"
fi
# $(pwd) more reliable than $PWD
echo "checking $(pwd)"
echo
matches="$(git grep -Ei \
-e 'AWS_ACCESS_KEY.*=.*[[:alnum:]]+' \
-e 'AWS_SECRET_KEY.*=.*[[:alnum:]]+' \
-e 'AWS_SECRET_ACCESS_KEY.*=.*[[:alnum:]]+' \
-e 'AWS_SESSION_TOKEN.*=.*[[:alnum:]]+' \
|| :
)"
if [ -f .gitallowed ]; then
# makes not difference, .gitallowed is exempted next anyway
#matches="$(grep -Ev -f .gitallowed <<< "$matches" | grep -Fv -f .gitallowed || :)"
matches="$(grep -Ev -f .gitallowed <<< "$matches" || :)"
fi
matches="$(grep -Ev -e "^${0##*/}:[[:space:]]+-e[[:space:]]+'AWS_" -e '^.bash.d/aws.sh:' -e '^.gitallowed:' <<< "$matches" || :)"
if [ -n "$matches" ]; then
# dangerous, fails silently and suppressed legitimate matches
#grep -v -f "$gitallowed" |
#grep -v -e '\.bash\.d/aws.sh:' \
# -e "${0##*/}:" |
# shellcheck disable=SC2001
sed 's/\(=.....\).*/\1....../' <<< "$matches"
echo
echo "DANGER: potential AWS credentials found in Git!!"
exit 1
fi
time_taken "$start_time"
section2 "OK: no AWS credentials found in Git"
echo
此处可能存在不合适展示的内容,页面不予展示。您可通过相关编辑功能自查并修改。
如您确认内容无涉及 不当用语 / 纯广告导流 / 暴力 / 低俗色情 / 侵权 / 盗版 / 虚假 / 无价值内容或违法国家有关法律法规的内容,可点击提交进行申诉,我们将尽快为您处理。