From 4600a75ec37b7db5c41051a976a708093008d3d7 Mon Sep 17 00:00:00 2001 From: Adam Koyuncu <50804772+adamkoy@users.noreply.github.com> Date: Mon, 28 Sep 2026 09:53:28 -0300 Subject: [PATCH 1/7] ci: scan for committed secrets with gitleaks-action Public repos cannot call private m0-pipelines. Use the public gitleaks/gitleaks-action that other orgs already run. --- .github/workflows/secret-scan.yml | 43 +++++++++++++++++++++++++++++++ 1 file changed, 43 insertions(+) create mode 100644 .github/workflows/secret-scan.yml diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml new file mode 100644 index 0000000..655e3fb --- /dev/null +++ b/.github/workflows/secret-scan.yml @@ -0,0 +1,43 @@ +############################################################################### +# Secret scan — public Gitleaks action +# +# https://github.com/gitleaks/gitleaks-action +# Org repos need a free GITLEAKS_LICENSE (gitleaks.io) as an Actions secret. +# Comments and SARIF upload are off so a finding is not published on a public PR. +############################################################################### + +name: Secret scan + +on: + pull_request: + types: [opened, synchronize, reopened] + push: + branches: [main] + schedule: + - cron: "0 3 1 * *" + workflow_dispatch: + +permissions: + contents: read + +jobs: + gitleaks: + name: Secret Scan (Gitleaks) + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - name: Checkout repository + # actions/checkout v4.3.1 + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 + with: + fetch-depth: 0 + persist-credentials: false + + - name: Run Gitleaks + # gitleaks/gitleaks-action v3.0.0 + uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e + env: + GITHUB_TOKEN: ${ secrets.GITHUB_TOKEN } + GITLEAKS_LICENSE: ${ secrets.GITLEAKS_LICENSE } + GITLEAKS_ENABLE_COMMENTS: "false" + GITLEAKS_ENABLE_UPLOAD_ARTIFACT: "false" From a045177b6a5e5fff116f1e0a2a7523a74074fef7 Mon Sep 17 00:00:00 2001 From: Adam Koyuncu <50804772+adamkoy@users.noreply.github.com> Date: Mon, 28 Sep 2026 10:01:28 -0300 Subject: [PATCH 2/7] fix: pass Gitleaks token and license as Actions expressions The previous commit stored the expressions as literal text, so the scan never received GITHUB_TOKEN or GITLEAKS_LICENSE. --- .github/workflows/secret-scan.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml index 655e3fb..e64cd68 100644 --- a/.github/workflows/secret-scan.yml +++ b/.github/workflows/secret-scan.yml @@ -37,7 +37,7 @@ jobs: # gitleaks/gitleaks-action v3.0.0 uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e env: - GITHUB_TOKEN: ${ secrets.GITHUB_TOKEN } - GITLEAKS_LICENSE: ${ secrets.GITLEAKS_LICENSE } + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITLEAKS_LICENSE: ${{ secrets.GITLEAKS_LICENSE }} GITLEAKS_ENABLE_COMMENTS: "false" GITLEAKS_ENABLE_UPLOAD_ARTIFACT: "false" From 45c7e15278d970b81584cdc189819cfa264f6e71 Mon Sep 17 00:00:00 2001 From: Adam Koyuncu <50804772+adamkoy@users.noreply.github.com> Date: Mon, 28 Sep 2026 15:46:40 -0300 Subject: [PATCH 3/7] ci: load the org Gitleaks baseline for EVM private keys The stock action misses deployer_pk-style keys. Fetch the shared baseline so a 32-byte hex is caught regardless of the variable name. --- .github/workflows/secret-scan.yml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml index e64cd68..5c3c836 100644 --- a/.github/workflows/secret-scan.yml +++ b/.github/workflows/secret-scan.yml @@ -4,6 +4,7 @@ # https://github.com/gitleaks/gitleaks-action # Org repos need a free GITLEAKS_LICENSE (gitleaks.io) as an Actions secret. # Comments and SARIF upload are off so a finding is not published on a public PR. +# Org baseline adds the EVM 32-byte rules (deployer_pk, bare hex). ############################################################################### name: Secret scan @@ -33,11 +34,19 @@ jobs: fetch-depth: 0 persist-credentials: false + - name: Fetch org Gitleaks baseline + # EVM rules from m0-platform/secret-scan @ 640b598d5685d92449a7529bd29854823ee23481 + # gitleaks reads GITLEAKS_CONFIG. Comments stay off on public PRs. + run: | + curl -fsSL -o /tmp/m0-gitleaks.toml \ + https://raw.githubusercontent.com/m0-platform/secret-scan/640b598d5685d92449a7529bd29854823ee23481/.github/actions/secret-scan/gitleaks.toml + - name: Run Gitleaks # gitleaks/gitleaks-action v3.0.0 uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITLEAKS_LICENSE: ${{ secrets.GITLEAKS_LICENSE }} + GITLEAKS_CONFIG: /tmp/m0-gitleaks.toml GITLEAKS_ENABLE_COMMENTS: "false" GITLEAKS_ENABLE_UPLOAD_ARTIFACT: "false" From 03b1c6b7e2449c9b0ded067edc06be852a67bcbe Mon Sep 17 00:00:00 2001 From: Adam Koyuncu <50804772+adamkoy@users.noreply.github.com> Date: Mon, 28 Sep 2026 16:14:23 -0300 Subject: [PATCH 4/7] ci: scan the full repo history with the org Gitleaks workflow Call the pinned secret-scan workflow so EVM rules apply and every commit in the repo is scanned, not only the pull request diff. --- .github/workflows/secret-scan.yml | 38 ++++++------------------------- 1 file changed, 7 insertions(+), 31 deletions(-) diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml index 5c3c836..5f4d2f2 100644 --- a/.github/workflows/secret-scan.yml +++ b/.github/workflows/secret-scan.yml @@ -1,10 +1,9 @@ ############################################################################### -# Secret scan — public Gitleaks action +# Secret scan # -# https://github.com/gitleaks/gitleaks-action -# Org repos need a free GITLEAKS_LICENSE (gitleaks.io) as an Actions secret. -# Comments and SARIF upload are off so a finding is not published on a public PR. -# Org baseline adds the EVM 32-byte rules (deployer_pk, bare hex). +# Calls the public org scanner at a pinned commit. That commit carries the EVM +# baseline (deployer_pk and bare 32-byte hex). gitleaks git scans the full +# history of this repo, not only the commits in the pull request. ############################################################################### name: Secret scan @@ -24,29 +23,6 @@ permissions: jobs: gitleaks: name: Secret Scan (Gitleaks) - runs-on: ubuntu-latest - timeout-minutes: 10 - steps: - - name: Checkout repository - # actions/checkout v4.3.1 - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 - with: - fetch-depth: 0 - persist-credentials: false - - - name: Fetch org Gitleaks baseline - # EVM rules from m0-platform/secret-scan @ 640b598d5685d92449a7529bd29854823ee23481 - # gitleaks reads GITLEAKS_CONFIG. Comments stay off on public PRs. - run: | - curl -fsSL -o /tmp/m0-gitleaks.toml \ - https://raw.githubusercontent.com/m0-platform/secret-scan/640b598d5685d92449a7529bd29854823ee23481/.github/actions/secret-scan/gitleaks.toml - - - name: Run Gitleaks - # gitleaks/gitleaks-action v3.0.0 - uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - GITLEAKS_LICENSE: ${{ secrets.GITLEAKS_LICENSE }} - GITLEAKS_CONFIG: /tmp/m0-gitleaks.toml - GITLEAKS_ENABLE_COMMENTS: "false" - GITLEAKS_ENABLE_UPLOAD_ARTIFACT: "false" + permissions: + contents: read + uses: m0-platform/secret-scan/.github/workflows/secret-scan.yml@640b598d5685d92449a7529bd29854823ee23481 From 619400250ea711ed8e4a33cf50fd4cc63c9cf8f8 Mon Sep 17 00:00:00 2001 From: Adam Koyuncu <50804772+adamkoy@users.noreply.github.com> Date: Tue, 29 Sep 2026 09:38:17 -0300 Subject: [PATCH 5/7] ci: pin the Gitleaks baseline that ignores 1Password op:// references Vault pointers are not secrets. The key is injected by the op CLI at runtime. --- .github/workflows/secret-scan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml index 5f4d2f2..118c63a 100644 --- a/.github/workflows/secret-scan.yml +++ b/.github/workflows/secret-scan.yml @@ -25,4 +25,4 @@ jobs: name: Secret Scan (Gitleaks) permissions: contents: read - uses: m0-platform/secret-scan/.github/workflows/secret-scan.yml@640b598d5685d92449a7529bd29854823ee23481 + uses: m0-platform/secret-scan/.github/workflows/secret-scan.yml@3272da02553e76c6f4b62f1ce64334053b8b73b6 From 705130df74a6f22f5c3ab446271fc13566b9552d Mon Sep 17 00:00:00 2001 From: Adam Koyuncu <50804772+adamkoy@users.noreply.github.com> Date: Tue, 29 Sep 2026 09:44:20 -0300 Subject: [PATCH 6/7] ci: track secret-scan@main so allow-list updates do not need a pin bump False-positive rules can change in one place while these callers stay put. --- .github/workflows/secret-scan.yml | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml index 118c63a..1279028 100644 --- a/.github/workflows/secret-scan.yml +++ b/.github/workflows/secret-scan.yml @@ -1,9 +1,8 @@ ############################################################################### # Secret scan # -# Calls the public org scanner at a pinned commit. That commit carries the EVM -# baseline (deployer_pk and bare 32-byte hex). gitleaks git scans the full -# history of this repo, not only the commits in the pull request. +# Calls the public org scanner on main. Allow-list updates there apply on the +# next run, with no pin bump in this repo. gitleaks git scans the full history. ############################################################################### name: Secret scan @@ -25,4 +24,4 @@ jobs: name: Secret Scan (Gitleaks) permissions: contents: read - uses: m0-platform/secret-scan/.github/workflows/secret-scan.yml@3272da02553e76c6f4b62f1ce64334053b8b73b6 + uses: m0-platform/secret-scan/.github/workflows/secret-scan.yml@main From f4e9b6cac8a0363f30eed843960be895b8a74306 Mon Sep 17 00:00:00 2001 From: Adam Koyuncu Date: Thu, 1 Oct 2026 11:57:19 -0300 Subject: [PATCH 7/7] ci: re-run secret scan against the org baseline