Skip to content

ci: add pinned gitleaks secret-scan job (#49) - #51

Merged
CodeSolutionsLLC merged 1 commit into
mainfrom
ci/49-gitleaks
Sep 27, 2026
Merged

CodeSolutionsLLC merged 1 commit into
mainfrom
ci/49-gitleaks

Conversation

@CodeSolutionsLLC

@CodeSolutionsLLC CodeSolutionsLLC commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Thanks for the pull request. See CONTRIBUTING.md for how changes land on main.

Summary

Add a fail-hard Secret scan sibling job to .github/workflows/validate.yml. It installs the official gitleaks binary (pinned and sha256-verified) and runs gitleaks detect on pull requests and pushes to main.

No third-party GitHub Action. The binary install mirrors the Workflow lint actionlint pattern: download the release tarball and checksums file, require the expected digest line, then sha256sum -c.

permissions: contents: read is unchanged. The job uses the default GITHUB_TOKEN only. Default gitleaks config; no allowlist file.

Related issue

Closes #49

Fixes #49

Pin

How to verify

Secret scan job is green on this PR (validate run on 8aee932: Markdown structure, Workflow lint, and Secret scan all succeeded).

Local check before push: gitleaks 8.30.1 detect --source . --verbose --redact --no-banner reported no leaks, and actionlint 1.7.12 reported no findings on .github/workflows/validate.yml.

Checklist

  • Evidence recorded. Summary and how to verify are filled in (commands, tests, or links). See verify and playbooks/verify.md.
  • CI green. Required checks on this pull request are passing, including validate.
  • No secrets. The pull request body and diff have no tokens, PATs, private config, or exploit details. Report security issues privately — SECURITY.md.
  • CODEOWNERS human merge (no self-merge). Authors wait for an independent human review and merge. Reviewers are listed in .github/CODEOWNERS. See no-self-merge and human-gate.
  • Public language safe. No private credentials, internal roster names, or private links.
Open in Web Open in Cursor 

Install official gitleaks 8.30.1 with sha256 verification and fail
validate when detect finds secrets. Same binary-install pattern as
Workflow lint; no third-party Action.

Co-authored-by: Code Solutions LLC <CodeSolutionsLLC@users.noreply.github.com>
@CodeSolutionsLLC

Copy link
Copy Markdown
Owner Author

Human VERIFY PASS (Computer)

  • Paths: .github/workflows/validate.yml only
  • Secret scan sibling: pinned gitleaks 8.30.1 sha256 551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb (matches release checksums linux_x64)
  • No third-party Action; contents: read; fail-hard; timeout 10
  • CI green on head 8aee932 (Markdown structure, Workflow lint, Secret scan, CodeQL Analyze)

Await Code merge. Do not self-merge.

@CodeSolutionsLLC
CodeSolutionsLLC merged commit a8b1d5b into main Sep 27, 2026
5 checks passed
@CodeSolutionsLLC
CodeSolutionsLLC deleted the ci/49-gitleaks branch September 27, 2026 23:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI: optional gitleaks job (public-safe, pinned binary)

2 participants