Files

80 lines
1.6 KiB
Nix

{
lib,
buildPythonPackage,
fetchFromGitHub,
gibberish-detector,
mock,
pkgs,
pyahocorasick,
pytest7CheckHook,
pyyaml,
requests,
responses,
setuptools,
unidiff,
writableTmpDirAsHomeHook,
withGibberish ? true,
withWordList ? true,
}:
buildPythonPackage rec {
pname = "detect-secrets";
version = "1.5.0";
pyproject = true;
src = fetchFromGitHub {
owner = "Yelp";
repo = "detect-secrets";
tag = "v${version}";
hash = "sha256-pNLAZUJhjZ3b01XaltJUJ9O7Blv6/pHQrRvURe7MJ5A=";
leaveDotGit = true;
};
build-system = [ setuptools ];
dependencies = [
pyyaml
requests
]
++ lib.optionals withGibberish optional-dependencies.gibberish
++ lib.optionals withWordList optional-dependencies.word_list;
optional-dependencies = {
gibberish = [
gibberish-detector
];
word_list = [
pyahocorasick
];
};
nativeCheckInputs = [
mock
pytest7CheckHook
responses
unidiff
pkgs.gitMinimal
writableTmpDirAsHomeHook
];
disabledTests = [
# Tests are failing for various reasons. Needs to be adjusted with the next update
"test_basic"
"test_handles_each_path_separately"
"test_handles_multiple_directories"
"test_make_decisions"
"test_saves_to_baseline"
"test_start_halfway"
];
pythonImportsCheck = [ "detect_secrets" ];
meta = {
description = "Enterprise friendly way of detecting and preventing secrets in code";
homepage = "https://github.com/Yelp/detect-secrets";
changelog = "https://github.com/Yelp/detect-secrets/releases/tag/${src.tag}";
license = lib.licenses.asl20;
maintainers = [ ];
};
}