Spaces:
Runtime error
Runtime error
Download security_check.py from ArtemisAI/Level-1-Project-2-Text-Summarization: direct link, hf CLI and curl.
- Browser
- Download file 3.07 kB
-
https://huggingface.co/spaces/ArtemisAI/Level-1-Project-2-Text-Summarization/resolve/main/security_check.py
- Command line
-
hf download hf://spaces/ArtemisAI/Level-1-Project-2-Text-Summarization/security_check.py
-
curl -L -o security_check.py https://huggingface.co/spaces/ArtemisAI/Level-1-Project-2-Text-Summarization/resolve/main/security_check.py
3.07 kB
| #!/usr/bin/env python3 | |
| """ | |
| Security check script to ensure no sensitive data is present before pushing to repositories. | |
| """ | |
| import os | |
| import re | |
| from pathlib import Path | |
| def check_for_sensitive_data(): | |
| """ | |
| Scans project files for potential sensitive data patterns. | |
| """ | |
| sensitive_patterns = [ | |
| r'token\s*=\s*["\'][^"\']+["\']', # token = "value" | |
| r'password\s*=\s*["\'][^"\']+["\']', # password = "value" | |
| r'api_key\s*=\s*["\'][^"\']+["\']', # api_key = "value" | |
| r'secret\s*=\s*["\'][^"\']+["\']', # secret = "value" | |
| r'hf_[a-zA-Z0-9]{34}', # HuggingFace token pattern | |
| r'ghp_[a-zA-Z0-9]{36}', # GitHub personal access token | |
| r'sk-[a-zA-Z0-9]{48}', # OpenAI API key pattern | |
| ] | |
| files_to_check = [ | |
| '*.py', '*.md', '*.txt', '*.json', '*.yaml', '*.yml' | |
| ] | |
| issues_found = [] | |
| project_root = Path('.') | |
| for pattern in files_to_check: | |
| for file_path in project_root.rglob(pattern): | |
| # Skip hidden files and cache directories | |
| if any(part.startswith('.') for part in file_path.parts): | |
| continue | |
| if '__pycache__' in str(file_path): | |
| continue | |
| try: | |
| with open(file_path, 'r', encoding='utf-8') as f: | |
| content = f.read() | |
| for line_num, line in enumerate(content.splitlines(), 1): | |
| # Skip comment lines and pattern definitions | |
| if line.strip().startswith('#') or 'r\'' in line: | |
| continue | |
| for sensitive_pattern in sensitive_patterns: | |
| if re.search(sensitive_pattern, line, re.IGNORECASE): | |
| issues_found.append({ | |
| 'file': str(file_path), | |
| 'line': line_num, | |
| 'pattern': sensitive_pattern, | |
| 'content': line.strip() | |
| }) | |
| except (UnicodeDecodeError, PermissionError): | |
| # Skip binary files or files we can't read | |
| continue | |
| return issues_found | |
| def main(): | |
| print("π Scanning for sensitive data in project files...") | |
| issues = check_for_sensitive_data() | |
| if not issues: | |
| print("β No sensitive data patterns detected!") | |
| print("β Project is safe to push to public repositories.") | |
| return True | |
| else: | |
| print(f"β οΈ Found {len(issues)} potential sensitive data issues:") | |
| for issue in issues: | |
| print(f" π {issue['file']}:{issue['line']}") | |
| print(f" Pattern: {issue['pattern']}") | |
| print(f" Content: {issue['content'][:80]}{'...' if len(issue['content']) > 80 else ''}") | |
| print() | |
| print("β Please review and remove sensitive data before pushing!") | |
| return False | |
| if __name__ == "__main__": | |
| main() | |