Lint files with rules and fix them
Lint files with rules and fix them
Write rules that say what a file may not hold, report each finding in the form a CI system reads, and apply the fixes. The rule fields are on pattern files.
$ cat rules.trex
rule cardnum error "card number ending ${card:last4}" = \{card}:card
fix cardnum = ****
rule todo note "a TODO left in ${path:name}" = "TODO"
$ cat app.conf
host = 10.0.0.5
pay 4111 1111 1111 1111 now
# TODO rotate
Report the findings
$ trex scan --rules rules.trex app.conf
app.conf:2:5: error: card number ending 1111 [cardnum]
fix: "****"
app.conf:3:3: note: a TODO left in app.conf [todo]
A finding of an error rule fails the run, so a CI step stops on it.
Annotate a CI run
--github writes each finding as a GitHub workflow annotation, and --sarif one SARIF 2.1.0
document for a code-scanning upload. The CLI writes a path as it was given; PowerShell writes the
full path of the file it resolved, run here in C:\Temp\demo:
$ trex scan --rules rules.trex --github app.conf
::error file=app.conf,line=2,col=5,endLine=2,endColumn=24,title=cardnum::card number ending 1111
::notice file=app.conf,line=3,col=3,endLine=3,endColumn=7,title=todo::a TODO left in app.conf
Apply the fixes
Look at the diff the fixes make, then write them:
$ trex scan --rules rules.trex --fix --dry-run app.conf
--- app.conf
+++ app.conf
@@ -1,3 +1,3 @@
host = 10.0.0.5
-pay 4111 1111 1111 1111 now
+pay **** now
# TODO rotate
--fix without --dry-run writes them, and --interactive puts each to you.