I'm trying to integrate the AWS Git secrets scan pipe in my pipeline (https://bitbucket.org/atlassian/git-secrets-scan/src/master/); however, I can't get the `FILES` filter to work, and the documentation doesn't give much help.
My simple pipeline builds a .NET Core 2.2 application, and checks for hardcoded AWS secrets in the source code:
image: mcr.microsoft.com/dotnet/core/sdk:2.2
pipelines:
default:
- step:
name: Build
caches:
- dotnetcore
script:
- dotnet build
- step:
name: Analyse
script:
- pipe: atlassian/git-secrets-scan:0.4.1
variables:
FILES: '*.cs'
However, when the pipeline runs, I see the following:
<span>Traceback (most recent call last):</span><span> File "/pipe.py", line 112, in <module></span><span> main()</span><span> File "/pipe.py", line 104, in main</span><span> raise Exception(result.stderr)</span><span>Exception: grep: *.cs: No such file or directory</span><span>INFO: Executing the pipe...</span>
If I remove the FILES setting (so it scans all files) then the pipeline runs correctly, although the Git secrets pipe fails with false positives on a project file (which is why I wanted the file filter in the first place).
Have I set up the pipe correctly? And how can I add other file types to the filter expression?