diff --git a/docs/codacy-rules.yaml b/docs/codacy-rules.yaml index 9c67766..7e5c4aa 100644 --- a/docs/codacy-rules.yaml +++ b/docs/codacy-rules.yaml @@ -625,4 +625,20 @@ rules: impact: HIGH confidence: HIGH references: - - https://kubernetes.io/blog/2025/11/11/ingress-nginx-retirement/ \ No newline at end of file + - https://kubernetes.io/blog/2025/11/11/ingress-nginx-retirement/ + - id: codacy.yaml.security.hard-coded-tokens + severity: ERROR + languages: + - generic + patterns: + - pattern-regex: '(?i)^\s*[\w-]*[_-]token[_-]?[\w-]*\s*:\s*["'']?[^\s"'']+["'']?\s*$' + message: Hardcoded tokens are a security risk. They can be easily found by attackers and used to gain unauthorized access to the system. + metadata: + owasp: + - A3:2017 Sensitive Data Exposure + description: Hardcoded tokens are a security risk. + category: security + technology: + - yaml + impact: HIGH + confidence: MEDIUM \ No newline at end of file diff --git a/internal/docgen/parsing.go b/internal/docgen/parsing.go index b643faa..db006b5 100644 --- a/internal/docgen/parsing.go +++ b/internal/docgen/parsing.go @@ -494,51 +494,53 @@ func getCodacySubCategory(category Category, OWASPCategories []string) SubCatego if category == Security && len(OWASPCategories) > 0 { standardizeCategory := standardizeCategory(OWASPCategories[0]) switch standardizeCategory { - case "a1:2017-injection": - return InputValidation - case "a1:2021-broken-access-control": - return InsecureStorage - case "a2:2017-broken-authentication": - return Auth - case "a2:2021-cryptographic-failures": - return Cryptography - case "a3:2017-sensitive-data-exposure": - return Visibility - case "a3:2021-injection": - return InputValidation - case "a4:2017-xml-external-entities-(xxe)": - return InputValidation - case "a4:2021-insecure-design": - return Other - case "a5:2017-broken-access-control": - return InsecureStorage - case "a5:2017-sensitive-data-exposure": - return InsecureStorage - case "a5:2021-security-misconfiguration": - return Other - case "a6:2017-misconfiguration", - "a6:2017-security-misconfiguration": - return Other - case "a6:2021-vulnerable-and-outdated-components": - return InsecureModulesLibraries - case "a7:2017-cross-site-scripting-(xss)": - return InputValidation - case "a7:2021-identification-and-authentication-failures": - return Auth - case "a8:2017-insecure-deserialization": - return InputValidation - case "a8:2021-software-and-data-integrity-failures": - return UnexpectedBehaviour - case "a9:2017-using-components-with-known-vulnerabilities": - return InsecureModulesLibraries - case "a9:2021-security-logging-and-monitoring-failures": - return Visibility - case "a10:2017-insufficient-logging-&-monitoring": - return Visibility - case "a10:2021-server-side-request-forgery-(ssrf)": - return InputValidation - default: - panic(fmt.Sprintf("unknown subcategory: %s -> %s", standardizeCategory, OWASPCategories[0])) + case "a1:2017-injection": + return InputValidation + case "a1:2021-broken-access-control": + return InsecureStorage + case "a2:2017-broken-authentication": + return Auth + case "a2:2021-cryptographic-failures": + return Cryptography + case "a3:2017-sensitive-data-exposure": + return Visibility + case "a3:2021-injection": + return InputValidation + case "a4:2017-xml-external-entities-(xxe)": + return InputValidation + case "a4:2021-insecure-design": + return Other + case "a5:2017-broken-access-control": + return InsecureStorage + case "a5:2017-sensitive-data-exposure": + return InsecureStorage + case "a5:2021-security-misconfiguration": + return Other + case "a6:2017-misconfiguration", + "a6:2017-security-misconfiguration": + return Other + case "a6:2021-vulnerable-and-outdated-components": + return InsecureModulesLibraries + case "a7:2017-cross-site-scripting-(xss)": + return InputValidation + case "a7:2021-identification-and-authentication-failures": + return Auth + case "a8:2017-insecure-deserialization": + return InputValidation + case "a8:2021-software-and-data-integrity-failures": + return UnexpectedBehaviour + case "a9:2017-using-components-with-known-vulnerabilities": + return InsecureModulesLibraries + case "a9:2021-security-logging-and-monitoring-failures": + return Visibility + case "a10:2017-insufficient-logging-&-monitoring": + return Visibility + case "a10:2021-server-side-request-forgery-(ssrf)": + return InputValidation + case "a10:2021-server-side-request-forgery": + return InputValidation + default: + panic(fmt.Sprintf("unknown subcategory: %s -> %s", standardizeCategory, OWASPCategories[0])) } } return ""