From 8aee93217e4f97f6ca7e95565bcd9fdd36132783 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Sun, 27 Sep 2026 23:25:54 +0000 Subject: [PATCH] ci: add pinned gitleaks secret-scan job (#49) Install official gitleaks 8.30.1 with sha256 verification and fail validate when detect finds secrets. Same binary-install pattern as Workflow lint; no third-party Action. Co-authored-by: Code Solutions LLC --- .github/workflows/validate.yml | 34 ++++++++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 0458ef1..7e85b1d 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -110,3 +110,37 @@ jobs: - name: Lint workflows run: ./actionlint -color .github/workflows/*.yml + + gitleaks: + name: Secret scan + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - name: Checkout + uses: actions/checkout@v7 + with: + fetch-depth: 0 + + - name: Install gitleaks + env: + # gitleaks/gitleaks v8.30.1 linux/x64 release tarball. + # SHA256 is the linux_x64 line in gitleaks_8.30.1_checksums.txt + # (same digest as the GitHub release asset). + GITLEAKS_VERSION: "8.30.1" + GITLEAKS_SHA256: "551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb" + run: | + set -euo pipefail + version="${GITLEAKS_VERSION}" + expected="${GITLEAKS_SHA256}" + tarball="gitleaks_${version}_linux_x64.tar.gz" + checksums="gitleaks_${version}_checksums.txt" + base="https://github.com/gitleaks/gitleaks/releases/download/v${version}" + curl -fsSL -o "${tarball}" "${base}/${tarball}" + curl -fsSL -o "${checksums}" "${base}/${checksums}" + grep -qxF "${expected} ${tarball}" "${checksums}" + echo "${expected} ${tarball}" | sha256sum -c - + tar -xzf "${tarball}" gitleaks + ./gitleaks version + + - name: Scan for secrets + run: ./gitleaks detect --source . --verbose --redact --no-banner