Skip to content

Commit 39176e8

Browse files
authored
feat(crafter): redact secrets from AI coding sessions before CAS upload (#3368)
Signed-off-by: Jose I. Paris <jiparis@chainloop.dev>
1 parent e25fa85 commit 39176e8

20 files changed

Lines changed: 2616 additions & 207 deletions

‎app/cli/cmd/attestation_add.go‎

Lines changed: 14 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,7 @@ func newAttestationAddCmd() *cobra.Command {
4141
var artifactCASConn *grpc.ClientConn
4242
var annotationsFlag []string
4343
var noStrictValidation bool
44+
var skipSecretRedaction bool
4445
var policyInputFromFileFlag []string
4546
var policyInputFlag []string
4647
var appendFlag bool
@@ -102,17 +103,18 @@ func newAttestationAddCmd() *cobra.Command {
102103

103104
a, err := action.NewAttestationAdd(
104105
&action.AttestationAddOpts{
105-
ActionsOpts: ActionOpts,
106-
CASURI: viper.GetString(confOptions.CASAPI.viperKey),
107-
CASCAPath: viper.GetString(confOptions.CASCA.viperKey),
108-
ConnectionInsecure: apiInsecure(),
109-
RegistryServer: registryServer,
110-
RegistryUsername: registryUsername,
111-
RegistryPassword: registryPassword,
112-
LocalStatePath: attestationLocalStatePath,
113-
NoStrictValidation: noStrictValidation,
114-
MaxExtractEntries: maxExtractEntries,
115-
MaxExtractSize: int64(maxExtractSizeBytes),
106+
ActionsOpts: ActionOpts,
107+
CASURI: viper.GetString(confOptions.CASAPI.viperKey),
108+
CASCAPath: viper.GetString(confOptions.CASCA.viperKey),
109+
ConnectionInsecure: apiInsecure(),
110+
RegistryServer: registryServer,
111+
RegistryUsername: registryUsername,
112+
RegistryPassword: registryPassword,
113+
LocalStatePath: attestationLocalStatePath,
114+
NoStrictValidation: noStrictValidation,
115+
SkipSecretRedaction: skipSecretRedaction,
116+
MaxExtractEntries: maxExtractEntries,
117+
MaxExtractSize: int64(maxExtractSizeBytes),
116118
},
117119
)
118120
if err != nil {
@@ -200,6 +202,7 @@ func newAttestationAddCmd() *cobra.Command {
200202
flagAttestationID(cmd)
201203
cmd.Flags().StringVar(&kind, "kind", "", fmt.Sprintf("kind of the material to be recorded: %q", schemaapi.ListAvailableMaterialKind()))
202204
cmd.Flags().BoolVar(&noStrictValidation, "no-strict-validation", false, "skip strict schema validation for structured materials (SBOM_CYCLONEDX_JSON, OPENAPI_SPEC, ASYNCAPI_SPEC, OSSF_SCORECARD_JSON)")
205+
cmd.Flags().BoolVar(&skipSecretRedaction, "skip-secret-redaction", false, "store evidence exactly as captured, without redacting detected secrets first (CHAINLOOP_AI_CODING_SESSION). Recorded in the attestation so policies can reject it")
203206
cmd.Flags().StringArrayVar(&policyInputFromFileFlag, "policy-input-from-file", nil, "feed a policy input from a column of a CSV or JSON file, in the format [<policy>:]<input>=<file>[:<column>] (e.g. ignored_paths=exception.csv:Path); the values are APPENDED to any contract-declared value; an optional <policy>: prefix scopes the input to a single policy (matched by name or ref), otherwise it applies to every declaring policy; <column> is a single top-level column/field name and defaults to the input name; repeatable. The file is also recorded as EVIDENCE.")
204207
cmd.Flags().StringArrayVar(&policyInputFlag, "policy-input", nil, "set a policy input to a literal value that REPLACES (overrides) any contract-declared value for the input, in the format [<policy>:]<input>=<value> (e.g. min_iterations=10); use this to override a scalar input at run time; an optional <policy>: prefix scopes it to a single policy (matched by name or ref), otherwise it applies to every declaring policy; repeatable.")
205208
cmd.Flags().BoolVar(&appendFlag, "append", false, "reserved for a future release: will control whether --policy-input and --policy-input-from-file append to (rather than replace) the contract-declared value; has no effect yet")

‎app/cli/documentation/cli-reference.mdx‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -278,6 +278,7 @@ Options
278278
--registry-password string registry password, ($CHAINLOOP_REGISTRY_PASSWORD)
279279
--registry-server string OCI repository server, ($CHAINLOOP_REGISTRY_SERVER)
280280
--registry-username string registry username, ($CHAINLOOP_REGISTRY_USERNAME)
281+
--skip-secret-redaction store evidence exactly as captured, without redacting detected secrets first (CHAINLOOP_AI_CODING_SESSION). Recorded in the attestation so policies can reject it
281282
--value string value to be recorded
282283
```
283284

‎app/cli/pkg/action/attestation_add.go‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -42,6 +42,9 @@ type AttestationAddOpts struct {
4242
LocalStatePath string
4343
// NoStrictValidation skips strict schema validation
4444
NoStrictValidation bool
45+
// SkipSecretRedaction uploads evidence that would normally be scrubbed
46+
// exactly as captured. The bypass is recorded in the attestation.
47+
SkipSecretRedaction bool
4548
// MaxExtractEntries limits the number of entries extracted from an archive.
4649
// Zero defaults to materials.DefaultArchiveLimits().MaxEntries.
4750
MaxExtractEntries int
@@ -76,6 +79,10 @@ func NewAttestationAdd(cfg *AttestationAddOpts) (*AttestationAdd, error) {
7679
if cfg.NoStrictValidation {
7780
opts = append(opts, crafter.WithNoStrictValidation(cfg.NoStrictValidation))
7881
}
82+
if cfg.SkipSecretRedaction {
83+
cfg.Logger.Warn().Msg("secret redaction is disabled, evidence will be stored exactly as captured")
84+
opts = append(opts, crafter.WithSkipSecretRedaction(cfg.SkipSecretRedaction))
85+
}
7986

8087
defaults := materials.DefaultArchiveLimits()
8188
maxEntries := cfg.MaxExtractEntries

‎go.mod‎

Lines changed: 16 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -97,7 +97,6 @@ require (
9797
github.com/sigstore/timestamp-authority/v2 v2.1.3
9898
github.com/styrainc/regal v0.35.1
9999
github.com/youmark/pkcs8 v0.0.0-20240726163527-a2c0da244d78
100-
github.com/zricethezav/gitleaks/v8 v8.30.1
101100
gitlab.com/gitlab-org/security-products/analyzers/report/v5 v5.13.1
102101
go.step.sm/crypto v0.87.0
103102
google.golang.org/genproto/googleapis/api v0.0.0-20260803160001-6ac0973c030d
@@ -108,6 +107,7 @@ require github.com/vektah/gqlparser/v2 v2.5.36
108107

109108
require (
110109
github.com/XSAM/otelsql v0.43.0
110+
github.com/betterleaks/betterleaks v1.8.1
111111
github.com/golang-jwt/jwt/v5 v5.3.1
112112
github.com/moby/moby/api v1.55.0
113113
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.70.0
@@ -130,17 +130,14 @@ require (
130130
github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azkeys v1.5.0 // indirect
131131
github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/internal v1.2.0 // indirect
132132
github.com/AzureAD/microsoft-authentication-library-for-go v1.7.2 // indirect
133-
github.com/BobuSumisu/aho-corasick v1.0.3 // indirect
134133
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.33.0 // indirect
135134
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.57.0 // indirect
136135
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.57.0 // indirect
137-
github.com/Masterminds/goutils v1.1.1 // indirect
138136
github.com/Masterminds/semver/v3 v3.5.0 // indirect
139-
github.com/Masterminds/sprig/v3 v3.3.0 // indirect
140137
github.com/STARRY-S/zip v0.2.3 // indirect
141138
github.com/agnivade/levenshtein v1.2.1 // indirect
142139
github.com/anchore/go-struct-converter v0.1.0 // indirect
143-
github.com/andybalholm/brotli v1.2.0 // indirect
140+
github.com/andybalholm/brotli v1.2.1 // indirect
144141
github.com/antithesishq/antithesis-sdk-go v0.7.2-default-no-op // indirect
145142
github.com/antlr4-go/antlr/v4 v4.13.1 // indirect
146143
github.com/apparentlymart/go-textseg/v15 v15.0.0 // indirect
@@ -151,17 +148,16 @@ require (
151148
github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.36 // indirect
152149
github.com/aws/aws-sdk-go-v2/service/kms v1.55.0 // indirect
153150
github.com/aws/aws-sdk-go-v2/service/signin v1.5.4 // indirect
154-
github.com/aymanbagabas/go-osc52/v2 v2.0.1 // indirect
155151
github.com/bahlo/generic-list-go v0.2.0 // indirect
156152
github.com/bmatcuk/doublestar v1.3.4 // indirect
157153
github.com/bmatcuk/doublestar/v4 v4.8.1 // indirect
158154
github.com/bodgit/plumbing v1.3.0 // indirect
159-
github.com/bodgit/sevenzip v1.6.1 // indirect
155+
github.com/bodgit/sevenzip v1.6.2 // indirect
160156
github.com/bodgit/windows v1.0.1 // indirect
161157
github.com/buger/jsonparser v1.1.2 // indirect
162158
github.com/casbin/govaluate v1.3.0 // indirect
163159
github.com/cenkalti/backoff/v5 v5.0.3 // indirect
164-
github.com/charmbracelet/lipgloss v0.5.0 // indirect
160+
github.com/charlievieth/fastwalk v1.0.14 // indirect
165161
github.com/clipperhouse/uax29/v2 v2.7.0 // indirect
166162
github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2 // indirect
167163
github.com/containerd/errdefs v1.0.0 // indirect
@@ -174,13 +170,15 @@ require (
174170
github.com/cyphar/filepath-securejoin v0.6.1 // indirect
175171
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.1 // indirect
176172
github.com/distribution/reference v0.6.0 // indirect
173+
github.com/dlclark/regexp2 v1.12.0 // indirect
177174
github.com/dsnet/compress v0.0.2-0.20230904184137-39efe44ab707 // indirect
178175
github.com/dustin/go-humanize v1.0.1 // indirect
179176
github.com/dylibso/observe-sdk/go v0.0.0-20240819160327-2d926c5d788a // indirect
180177
github.com/ebitengine/purego v0.10.1 // indirect
181178
github.com/emirpasic/gods v1.18.1 // indirect
182179
github.com/envoyproxy/go-control-plane/envoy v1.37.0 // indirect
183180
github.com/envoyproxy/protoc-gen-validate v1.3.3 // indirect
181+
github.com/expr-lang/expr v1.17.8 // indirect
184182
github.com/fatih/color v1.19.0 // indirect
185183
github.com/fatih/semgroup v1.2.0 // indirect
186184
github.com/felixge/httpsnoop v1.1.0 // indirect
@@ -206,19 +204,20 @@ require (
206204
github.com/go-openapi/swag/typeutils v0.28.0 // indirect
207205
github.com/go-openapi/swag/yamlutils v0.28.0 // indirect
208206
github.com/go-playground/assert/v2 v2.2.0 // indirect
207+
github.com/go-sprout/sprout v1.0.3 // indirect
209208
github.com/go-viper/mapstructure/v2 v2.5.0 // indirect
210209
github.com/gobwas/glob v0.2.3 // indirect
211210
github.com/goccy/go-json v0.10.6 // indirect
212211
github.com/google/cel-go v0.30.0 // indirect
213212
github.com/google/gnostic-models v0.7.0 // indirect
213+
github.com/google/go-github/v72 v72.0.0 // indirect
214214
github.com/google/go-github/v88 v88.0.0 // indirect
215215
github.com/google/go-tpm v0.9.8 // indirect
216216
github.com/google/renameio/v2 v2.0.0 // indirect
217217
github.com/gorilla/handlers v1.5.2 // indirect
218218
github.com/h2non/filetype v1.1.3 // indirect
219219
github.com/hashicorp/go-version v1.9.0 // indirect
220220
github.com/hashicorp/yamux v0.1.2 // indirect
221-
github.com/huandu/xstrings v1.5.0 // indirect
222221
github.com/ianlancetaylor/demangle v0.0.0-20240805132620-81f5be970eca // indirect
223222
github.com/jackc/puddle/v2 v2.2.2 // indirect
224223
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
@@ -235,23 +234,21 @@ require (
235234
github.com/lestrrat-go/httprc/v3 v3.0.5 // indirect
236235
github.com/lestrrat-go/jwx/v3 v3.1.1 // indirect
237236
github.com/lestrrat-go/option/v2 v2.0.0 // indirect
238-
github.com/lucasb-eyer/go-colorful v1.4.0 // indirect
239237
github.com/lufia/plan9stats v0.0.0-20260330125221-c963978e514e // indirect
240-
github.com/mholt/archives v0.1.5 // indirect
238+
github.com/mholt/archives v0.1.6-0.20260429171216-ef71b7a32fae // indirect
241239
github.com/miekg/dns v1.1.62 // indirect
242240
github.com/mikelolasagasti/xz v1.0.1 // indirect
243241
github.com/minio/crc64nvme v1.1.1 // indirect
244242
github.com/minio/highwayhash v1.0.4 // indirect
245243
github.com/minio/md5-simd v1.1.2 // indirect
246-
github.com/minio/minlz v1.0.1 // indirect
244+
github.com/minio/minlz v1.1.1 // indirect
247245
github.com/mitchellh/copystructure v1.2.0 // indirect
248246
github.com/mitchellh/reflectwalk v1.0.2 // indirect
249247
github.com/moby/docker-image-spec v1.3.1 // indirect
250248
github.com/moby/go-archive v0.3.0 // indirect
251249
github.com/moby/moby/client v0.5.1 // indirect
252250
github.com/moby/sys/user v0.4.1 // indirect
253251
github.com/moby/sys/userns v0.1.0 // indirect
254-
github.com/muesli/termenv v0.15.1 // indirect
255252
github.com/natefinch/atomic v1.0.1 // indirect
256253
github.com/nats-io/jwt/v2 v2.8.2 // indirect
257254
github.com/nats-io/nkeys v0.4.16 // indirect
@@ -265,20 +262,23 @@ require (
265262
github.com/pb33f/ordered-map/v2 v2.3.1 // indirect
266263
github.com/pelletier/go-toml v1.9.5 // indirect
267264
github.com/philhofer/fwd v1.2.0 // indirect
268-
github.com/pierrec/lz4/v4 v4.1.22 // indirect
265+
github.com/pierrec/lz4/v4 v4.1.26 // indirect
269266
github.com/pjbgf/sha1cd v0.6.0 // indirect
270267
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
271268
github.com/pkg/xattr v0.4.12 // indirect
269+
github.com/pkoukk/tiktoken-go v0.1.8 // indirect
272270
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
273271
github.com/power-devops/perfstat v0.0.0-20240221224432-82ca36839d55 // indirect
274272
github.com/rcrowley/go-metrics v0.0.0-20250401214520-65e299d6c5c9 // indirect
273+
github.com/rrethy/ahocorasick v1.0.0 // indirect
275274
github.com/rs/xid v1.6.0 // indirect
276275
github.com/russross/blackfriday/v2 v2.1.0 // indirect
277276
github.com/sagikazarmark/locafero v0.11.0 // indirect
278277
github.com/segmentio/asm v1.2.1 // indirect
279278
github.com/sergi/go-diff v1.4.0 // indirect
280279
github.com/shirou/gopsutil/v4 v4.26.6 // indirect
281-
github.com/shopspring/decimal v1.4.0 // indirect
280+
github.com/shurcooL/githubv4 v0.0.0-20260209031235-2402fdf4a9ed // indirect
281+
github.com/shurcooL/graphql v0.0.0-20240915155400-7ee5256398cf // indirect
282282
github.com/sigstore/rekor-tiles/v2 v2.3.0 // indirect
283283
github.com/skeema/knownhosts v1.3.1 // indirect
284284
github.com/sorairolake/lzip-go v0.3.8 // indirect
@@ -296,8 +296,6 @@ require (
296296
github.com/transparency-dev/formats v0.1.1 // indirect
297297
github.com/ulikunitz/xz v0.5.15 // indirect
298298
github.com/valyala/fastjson v1.6.10 // indirect
299-
github.com/wasilibs/go-re2 v1.9.0 // indirect
300-
github.com/wasilibs/wazero-helpers v0.0.0-20240620070341-3dff1577cd52 // indirect
301299
github.com/x448/float16 v0.8.4 // indirect
302300
github.com/xanzy/ssh-agent v0.3.3 // indirect
303301
github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
@@ -320,7 +318,7 @@ require (
320318
go.yaml.in/yaml/v2 v2.4.4 // indirect
321319
go.yaml.in/yaml/v3 v3.0.5 // indirect
322320
go.yaml.in/yaml/v4 v4.0.0-rc.2 // indirect
323-
go4.org v0.0.0-20230225012048-214862532bf5 // indirect
321+
go4.org v0.0.0-20260112195520-a5071408f32f // indirect
324322
goa.design/goa/v3 v3.27.0 // indirect
325323
gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
326324
gopkg.in/ini.v1 v1.67.3 // indirect

0 commit comments

Comments
 (0)