Skip to content

Conversation

cpholguera
Copy link
Collaborator

@cpholguera cpholguera commented Sep 13, 2025

This PR adds gitleaks as a new tool for secrets scanning in mobile app testing and improves the handling of sensitive data demonstrations in MASTG-DEMO-0059 and MASTG-DEMO-0058.

Key changes include:

  • Introduction of gitleaks tool (MASTG-TOOL-0144) for detecting hardcoded credentials
  • Enhanced MASTG-DEMO-0059 with more realistic secret formats and improved documentation
  • Updated MASTG-DEMO-0058 with clearer explanations and evaluation scripts

Copy link
Contributor

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds gitleaks as a new tool for secrets scanning in mobile app testing and improves the handling of sensitive data demonstrations in MASTG-DEMO-0059 and MASTG-DEMO-0058.

Key changes include:

  • Introduction of gitleaks tool (MASTG-TOOL-0144) for detecting hardcoded credentials
  • Enhanced MASTG-DEMO-0059 with more realistic secret formats and improved documentation
  • Updated MASTG-DEMO-0058 with clearer explanations and evaluation scripts

Reviewed Changes

Copilot reviewed 12 out of 12 changed files in this pull request and generated 2 comments.

File Description
tools/generic/MASTG-TOOL-0144.md Adds gitleaks tool documentation for secrets scanning
demos/android/MASVS-STORAGE/MASTG-DEMO-0059/ Updates demo with enhanced secret formats and comprehensive evaluation methods
demos/android/MASVS-CRYPTO/MASTG-DEMO-0058/ Improves demo documentation and adds evaluation script

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

@cpholguera cpholguera requested a review from bernhste September 13, 2025 11:06
@cpholguera cpholguera changed the title Add gitleaks as MASTG-TOOL-0144 and improve MASTG-DEMO-0059 and MASTG-DEMO-0058 Improve MASTG-DEMO-0059 and MASTG-DEMO-0058 Sep 20, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant