feat: user config file, SARIF output, detector overrides, pre-commit hooks - #73
Conversation
ebb9d17 to
83613f4CompareThere was a problem hiding this comment.
Pull request overview
This PR closes the remaining feature gaps from #71 by adding user-configurable scanning behavior via a TOML config file, introducing SARIF output for Code Scanning integration, and expanding integration support via pre-commit hooks, while also reinstating CRITICAL severity handling across the reporting/exit-code pipeline.
Changes:
- Added
.keywatch.tomlsupport (custom rules, per-detector enable/disable + severity overrides, and config-driven exclude patterns). - Added
--formatwith SARIF 2.1.0 output generation alongside JSON. - Refactored hook install/uninstall into
src/hooks.rsand added pre-commit framework hook definitions.
Reviewed changes
Copilot reviewed 10 out of 11 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
| tests/scanner_tests.rs | Updates tests for new ScanArgs fields and run_scan signature. |
| src/scanner.rs | Accepts optional config, applies detector overrides, and merges config exclude patterns. |
| src/report.rs | Adds CRITICAL severity and implements SARIF report generation. |
| src/lib.rs | Loads config, selects JSON vs SARIF output, and routes hook commands through hooks module. |
| src/hooks.rs | Implements install_hook/uninstall_hook and hook-safety logic in the hooks module. |
| src/config.rs | Introduces config parsing/loading and applying custom rules/overrides/excludes to detectors. |
| src/cli.rs | Adds --config and --format CLI options plus OutputFormat enum. |
| README.md | Adds an architecture section and references the new diagram. |
| docs/architecture.svg | Adds an SVG architecture diagram for documentation. |
| CHANGELOG.md | Documents config, SARIF, CLI flag changes, and updated severity counts/run_scan signature. |
| .pre-commit-hooks.yaml | Adds pre-commit hook metadata for KeyWatch scanning. |
Suppressed comments (2)
src/report.rs:120
- SARIF
resultobjects requireruleId, but this struct currently serializesrule_id(snake_case), which breaks SARIF 2.1.0 schema expectations.
#[derive(Serialize)]
struct SarifResult {
rule_id: String,
level: &'static str,
message: SarifMessage,
src/report.rs:134
- SARIF location fields are currently serialized as
physical_location,artifact_location, andstart_line(snake_case). SARIF 2.1.0 expectsphysicalLocation,artifactLocation, andstartLine, so the report will not be schema-compliant.
#[derive(Serialize)]
struct SarifLocation {
physical_location: SarifPhysicalLocation,
}
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
7e20919 to
e543e6dCompare6cbb2bc to
90caf45Comparee543e6d to
699f621Comparea009937 to
e8b339fComparee8b339f to
3561e18Compare
Summary
Implements the remaining non-CI/CD feature gaps from #71: user-configurable
.keywatch.toml, SARIF output format, per-detector enable/disable and severity overrides, and pre-commit framework support.Changes
User Config (
.keywatch.toml)src/config.rsmodule for loading and parsing user config--config <path>or auto-detected (.keywatch.toml→keywatch.toml→.kw.toml)detectors.toml--excludeCLI flagExample config:
SARIF Output
--formatflag:key-watch scan <paths> --format sariferror, MEDIUM →warning, LOW →noteCRITICAL Severity
Severity::Criticalvariant (serialized asCRITICAL)from_string()now recognizes "CRITICAL"get_severity_counts(Critical counted with High)Per-Detector Enable/Disable
enabled = false)Pre-Commit Framework
.pre-commit-hooks.yamlfor use with pre-commitCRITICAL Severity Variant
This PR reinstates the CRITICAL severity level (also in PR #69, not yet in master) so users can flag high-value secrets (AWS root, GitHub PATs) above standard HIGH.
Future Work (not in this PR)