fix(git): detect secrets in renamed/copied files#4694
Open
PascalThuet wants to merge 3 commits intotrufflesecurity:mainfrom
Open
fix(git): detect secrets in renamed/copied files#4694PascalThuet wants to merge 3 commits intotrufflesecurity:mainfrom
PascalThuet wants to merge 3 commits intotrufflesecurity:mainfrom
Conversation
When a file is renamed using `git mv` or when git detects a 100% copy, the `git log --patch` output shows only: ``` similarity index 100% rename from fileA.txt rename to fileB.txt ``` Without any actual content diff, causing the scanner to miss secrets in the renamed file. This fix adds `--no-renames` to the git log and git diff commands, which disables git's rename detection. This causes git to treat renames as a delete + add operation, ensuring the full file content is shown for newly created files. Fixes trufflesecurity#4672 ## Changes - Add `--no-renames` flag to `RepoPath()` in gitparse.go - Add `--no-renames` flag to `Staged()` in gitparse.go - Add regression test `TestRenamedFileContainsSecret` ## Testing Created a test repository with: 1. Initial file with AWS credentials 2. Renamed file using `git mv` Before fix: Secret only reported in original file (now deleted) After fix: Secret correctly reported in renamed file
9499324 to
3124e79
Compare
camgunz
approved these changes
Feb 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #4672
When a file is renamed using
git mvor when git detects a file copy with 100% similarity, thegit log --patchoutput shows only metadata without actual file content:This causes the scanner to miss secrets in renamed/copied files because no content diff is generated.
Solution
Add
--no-renamesflag to git commands ingitparse.go. This disables git's rename detection, causing git to treat renames as delete + add operations, ensuring full file content is always shown in the diff output.Changes
--no-renamestoRepoPath()git log command--no-renamestoStaged()git diff commandTestRenamedFileContainsSecretPerformance Impact
Test Plan