From 382f9a8244997c8d3daaba106131561ed58a2c49 Mon Sep 17 00:00:00 2001 From: davidus27 Date: Tue, 5 May 2026 13:49:12 +0200 Subject: [PATCH 1/2] add trufflehog only verified as a new value to the k8s templates --- helm/gsast/templates/_helpers.tpl | 4 ++++ helm/gsast/values.yaml | 4 ++++ 2 files changed, 8 insertions(+) diff --git a/helm/gsast/templates/_helpers.tpl b/helm/gsast/templates/_helpers.tpl index cf65f90..fe464db 100644 --- a/helm/gsast/templates/_helpers.tpl +++ b/helm/gsast/templates/_helpers.tpl @@ -77,6 +77,10 @@ Common environment variables for both API and Worker - name: NO_PROXY value: {{ .Values.environment.noProxy }} {{- end }} +{{- if .Values.environment.trufflehogOnlyVerified }} +- name: TRUFFLEHOG_ONLY_VERIFIED + value: {{ .Values.environment.trufflehogOnlyVerified | quote }} +{{- end }} - name: GITHUB_API_TOKEN valueFrom: secretKeyRef: diff --git a/helm/gsast/values.yaml b/helm/gsast/values.yaml index d6a08a2..31c728d 100644 --- a/helm/gsast/values.yaml +++ b/helm/gsast/values.yaml @@ -28,6 +28,10 @@ environment: httpsProxy: null noProxy: null + # TruffleHog configuration + # Set to "false" to include unverified secrets, "true" for only verified secrets + trufflehogOnlyVerified: "true" + # Custom GitLab CA configuration customGitlabCA: enabled: false From 77955b96d34525358e3bbaea634818b31cd5903f Mon Sep 17 00:00:00 2001 From: davidus27 Date: Wed, 6 May 2026 17:35:57 +0200 Subject: [PATCH 2/2] add TTL for scan results --- gsast-core/gsast_core/configs/__init__.py | 1 + gsast-core/gsast_core/configs/defaults.py | 2 ++ gsast-core/gsast_core/sastlib/results_storage.py | 3 +++ 3 files changed, 6 insertions(+) diff --git a/gsast-core/gsast_core/configs/__init__.py b/gsast-core/gsast_core/configs/__init__.py index 1a9f769..15108e7 100644 --- a/gsast-core/gsast_core/configs/__init__.py +++ b/gsast-core/gsast_core/configs/__init__.py @@ -25,6 +25,7 @@ SERVER_CHECK_PROJECT_STATUS_INTERVAL, SERVER_JOB_TIMEOUT, SERVER_JOB_RESULT_TTL, + REDIS_SCAN_RESULTS_TTL, REDIS_CACHE_DB, REDIS_TASKS_DB, REDIS_RULES_DB, diff --git a/gsast-core/gsast_core/configs/defaults.py b/gsast-core/gsast_core/configs/defaults.py index c09c236..599548a 100644 --- a/gsast-core/gsast_core/configs/defaults.py +++ b/gsast-core/gsast_core/configs/defaults.py @@ -26,6 +26,8 @@ SERVER_JOB_TIMEOUT: str = '15m' # minutes SERVER_JOB_RESULT_TTL: int = 3 * 60 * 60 * 24 # seconds +REDIS_SCAN_RESULTS_TTL: int = 7 * 24 * 60 * 60 # 7 days in seconds + REDIS_CACHE_DB: int = 0 REDIS_TASKS_DB: int = 1 REDIS_RULES_DB: int = 2 diff --git a/gsast-core/gsast_core/sastlib/results_storage.py b/gsast-core/gsast_core/sastlib/results_storage.py index c65a89e..18d2928 100644 --- a/gsast-core/gsast_core/sastlib/results_storage.py +++ b/gsast-core/gsast_core/sastlib/results_storage.py @@ -3,6 +3,7 @@ from typing import Dict, Optional, Any, List from pathlib import Path from redis.client import Redis +from gsast_core.configs import REDIS_SCAN_RESULTS_TTL from gsast_core.utils.safe_logging import log @@ -57,10 +58,12 @@ def store_scan_results(scans_redis: Redis, scan_id: str, project_url: str, scann 'scanner_type': scanner_type, 'updated_at': str(int(time.time())) }) + scans_redis.expire(results_key, REDIS_SCAN_RESULTS_TTL) # Add this project to the scan's project list projects_key = f"{scan_id}:projects" scans_redis.sadd(projects_key, project_url) + scans_redis.expire(projects_key, REDIS_SCAN_RESULTS_TTL) log.info(f"Successfully stored {len(results_paths)} {scanner_type} results for {project_url}") return True