Skip to content

Commit dc8fdbd

Browse files
authored
Merge pull request #88 from advanced-security/jwt-image-fp
Remove JWT FPs on images in GitHub private issues
2 parents b61043e + 3073599 commit dc8fdbd

File tree

2 files changed

+4
-4
lines changed

2 files changed

+4
-4
lines changed

jwt/README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,7 @@ Add these additional matches to the [Secret Scanning Custom Pattern](https://doc
4747
- Not Match:
4848

4949
```regex
50-
^eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9\.eyJrZXkiOiJrZXkxIiwiZXhwIjo[A-Za-z0-9_-]+(JlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCZhY3Rvcl9pZD0wJmtleV9pZD0wJnJlcG9faWQ9MCJ9|ZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmYWN0b3JfaWQ9MCZrZXlfaWQ9MCZyZXBvX2lkPTAifQ|mWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JmFjdG9yX2lkPTAma2V5X2lkPTAmcmVwb19pZD0wIn0)
50+
^eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIs
5151
```
5252

5353
</details>

jwt/patterns.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,9 +12,10 @@ patterns:
1212
[^0-9A-Za-z_.-]|\A
1313
end: |
1414
[^0-9A-Za-z_.=-]|\z
15-
# don't detect JWT that are used in private GitHub issues
15+
# don't match on JWT that are used in private GitHub issues - they now always start with:
16+
# {"iss":"github.com","aud":"raw.githubusercontent.com",
1617
additional_not_match:
17-
- ^eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9\.eyJrZXkiOiJrZXkxIiwiZXhwIjo[A-Za-z0-9_-]+(JlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCZhY3Rvcl9pZD0wJmtleV9pZD0wJnJlcG9faWQ9MCJ9|ZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmYWN0b3JfaWQ9MCZrZXlfaWQ9MCZyZXBvX2lkPTAifQ|mWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JmFjdG9yX2lkPTAma2V5X2lkPTAmcmVwb19pZD0wIn0)
18+
- ^eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIs
1819

1920
expected:
2021
- name: owasp-juice-shop.ts
@@ -29,4 +30,3 @@ patterns:
2930
- name: test_jwt.txt
3031
start_offset: 170
3132
end_offset: 381
32-

0 commit comments

Comments
 (0)