fix(git): detect secrets in renamed/copied files #4694
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #4672
When a file is renamed using
git mvor when git detects a file copy with 100% similarity, thegit log --patchoutput shows only metadata without actual file content:This causes the scanner to miss secrets in renamed/copied files because no content diff is generated.
Solution
Add
--no-renamesflag to git commands ingitparse.go. This disables git's rename detection, causing git to treat renames as delete + add operations, ensuring full file content is always shown in the diff output.Changes
--no-renamestoRepoPath()git log command--no-renamestoStaged()git diff commandTestRenamedFileContainsSecretPerformance Impact
Test Plan