Repository navigation
ci: add pinned gitleaks secret-scan job (#49) - #51
Merged
Merged
Conversation
Install official gitleaks 8.30.1 with sha256 verification and fail validate when detect finds secrets. Same binary-install pattern as Workflow lint; no third-party Action. Co-authored-by: Code Solutions LLC <CodeSolutionsLLC@users.noreply.github.com>
Owner
Author
|
Human VERIFY PASS (Computer)
Await Code merge. Do not self-merge. |
5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Thanks for the pull request. See CONTRIBUTING.md for how changes land on
main.Summary
Add a fail-hard Secret scan sibling job to
.github/workflows/validate.yml. It installs the official gitleaks binary (pinned and sha256-verified) and runsgitleaks detecton pull requests and pushes tomain.No third-party GitHub Action. The binary install mirrors the Workflow lint actionlint pattern: download the release tarball and checksums file, require the expected digest line, then
sha256sum -c.permissions: contents: readis unchanged. The job uses the defaultGITHUB_TOKENonly. Default gitleaks config; no allowlist file.Related issue
Closes #49
Fixes #49
Pin
How to verify
Secret scan job is green on this PR (validate run on
8aee932: Markdown structure, Workflow lint, and Secret scan all succeeded).Local check before push: gitleaks 8.30.1
detect --source . --verbose --redact --no-bannerreported no leaks, and actionlint 1.7.12 reported no findings on.github/workflows/validate.yml.Checklist