Skip to content

ci: add Gitleaks secret scan - #3

Open
adamkoy wants to merge 7 commits into
mainfrom
ci/gitleaks-action
Open

adamkoy wants to merge 7 commits into
mainfrom
ci/gitleaks-action

Conversation

@adamkoy

@adamkoy adamkoy commented Sep 28, 2026

Copy link
Copy Markdown

Summary

  • Adds the public gitleaks/gitleaks-action v3.0.0 on pull requests, pushes to main, and a monthly schedule.
  • Same workflow as foundry-template#9. The org secret GITLEAKS_LICENSE is already set.
  • PR comments and SARIF upload are off so a finding is not published on a public pull request. The job still fails if a leak is found.

Test plan

  • Secret Scan (Gitleaks) runs on this PR

adamkoy and others added 7 commits September 28, 2026 09:53
Public repos cannot call private m0-pipelines. Use the public
gitleaks/gitleaks-action that other orgs already run.
The previous commit stored the expressions as literal text, so the scan
never received GITHUB_TOKEN or GITLEAKS_LICENSE.
The stock action misses deployer_pk-style keys. Fetch the shared baseline so a 32-byte hex is caught regardless of the variable name.
Call the pinned secret-scan workflow so EVM rules apply and every commit in the repo is scanned, not only the pull request diff.
Vault pointers are not secrets. The key is injected by the op CLI at runtime.
False-positive rules can change in one place while these callers stay put.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant