- if not is_binary(full_path):
- try:
- fo = open(full_path, 'r')
- lines = fo.readlines()
- except IOError:
- logger.error('%s does not exist', full_path)
-
- for line in lines:
- # Check for sensitive content in project files
- for key, value in master_list.iteritems():
- regex = value['regex']
- desc = value['desc']
- if re.search(regex, line) and not re.search(project_list, line):
- logger.error('File contains violation: %s', full_path)
- logger.error('Flagged Content: %s', line.rstrip())
- logger.error('Matched Regular Exp: %s', regex)
- logger.error('Rationale: %s', desc.rstrip())
- with open(reports_dir + "contents-" + project + ".log",
- "a") \
- as gate_report:
- gate_report. \
- write('File contains violation: {0}\n'.
- format(full_path))
- gate_report. \
- write('Flagged Content: {0}'.
- format(line))
- gate_report. \
- write('Matched Regular Exp: {0}'.
- format(regex))
- gate_report. \
- write('Rationale: {0}\n'.
- format(desc.rstrip()))
- else:
- # Check if Binary is whitelisted
- hashlist = get_lists.GetLists()
- binary_hash = hashlist.binary_hash(project, full_path)
- if not binary_list.search(full_path):
- with open(full_path, 'rb') as afile:
- buf = afile.read()
- hasher.update(buf)
- if hasher.hexdigest() in binary_hash:
- logger.info('Found matching file hash for file: %s',
+ # Check if Binary is whitelisted
+ hashlist = get_lists.GetLists()
+ binary_hash = hashlist.binary_hash(project, full_path)
+ if is_binary(full_path) and not binary_list.search(full_path):
+ with open(full_path, 'rb') as afile:
+ buf = afile.read()
+ hasher.update(buf)
+ if hasher.hexdigest() in binary_hash:
+ logger.info('Found matching file hash for file: %s',