Skip to content

ci: add Gitleaks secret scan - #58

Open
adamkoy wants to merge 7 commits into
mainfrom
ci/gitleaks-action
Open

adamkoy wants to merge 7 commits into
mainfrom
ci/gitleaks-action

Conversation

@adamkoy

@adamkoy adamkoy commented Sep 28, 2026

Copy link
Copy Markdown

Summary

  • Adds the public gitleaks/gitleaks-action v3.0.0 on pull requests, pushes to main, and a monthly schedule.
  • Same workflow as foundry-template#9. The org secret GITLEAKS_LICENSE is already set.
  • PR comments and SARIF upload are off so a finding is not published on a public pull request. The job still fails if a leak is found.

Test plan

  • Secret Scan (Gitleaks) runs on this PR

Public repos cannot call private m0-pipelines. Use the public
gitleaks/gitleaks-action that other orgs already run.
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Changes to gas cost

Generated at commit: 3a49b8714ca86e3901895d646bb8ac29d4fc2816, compared to commit: 81ec16e7199d01a988d573a04e7b3b2991aa7c31

🧾 Summary (20% most significant diffs)

Contract Method Avg (+/-) %

Full diff report 👇
Contract Deployment Cost (+/-) Method Min (+/-) % Avg (+/-) % Median (+/-) % Max (+/-) % # Calls (+/-)
ERC20ExtendedHandler 766,606 (0) approve
burn
mint
transfer
transferFrom
31,355 (0)
41,828 (0)
381 (0)
477 (0)
488 (0)
0.00%
0.00%
0.00%
0.00%
0.00%
45,754 (-4)
46,293 (-10)
50,997 (+16)
57,621 (-29)
54,134 (-24)
-0.01%
-0.02%
+0.03%
-0.05%
-0.04%
51,303 (0)
44,691 (0)
62,063 (0)
60,896 (0)
60,925 (0)
0.00%
0.00%
0.00%
0.00%
0.00%
51,879 (0)
53,627 (0)
96,839 (0)
131,469 (0)
133,779 (0)
0.00%
0.00%
0.00%
0.00%
0.00%
12,854 (0)
12,951 (0)
12,964 (0)
12,670 (0)
12,812 (0)
ERC20ExtendedHarness 1,677,854 (-2,052) approve
burn
mint
transfer
transferFrom
26,013 (0)
24,108 (0)
28,461 (0)
24,097 (0)
24,582 (0)
0.00%
0.00%
0.00%
0.00%
0.00%
41,137 (-7)
29,707 (-6)
50,625 (+13)
31,606 (-12)
35,402 (-9)
-0.02%
-0.02%
+0.03%
-0.04%
-0.03%
45,973 (0)
28,711 (0)
51,269 (0)
28,871 (0)
31,873 (0)
0.00%
0.00%
0.00%
0.00%
0.00%
46,537 (0)
34,695 (0)
68,873 (0)
51,955 (0)
57,769 (0)
0.00%
0.00%
0.00%
0.00%
0.00%
14,663 (-9)
13,466 (0)
15,342 (0)
11,828 (0)
11,133 (0)

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

LCOV of commit 7e9e88f during Forge Coverage #191

Summary coverage rate:
  lines......: 95.4% (476 of 499 lines)
  functions..: 95.6% (153 of 160 functions)
  branches...: no data found

Files changed coverage rate: n/a

adamkoy and others added 6 commits September 28, 2026 10:01
The previous commit stored the expressions as literal text, so the scan
never received GITHUB_TOKEN or GITLEAKS_LICENSE.
The stock action misses deployer_pk-style keys. Fetch the shared baseline so a 32-byte hex is caught regardless of the variable name.
Call the pinned secret-scan workflow so EVM rules apply and every commit in the repo is scanned, not only the pull request diff.
Vault pointers are not secrets. The key is injected by the op CLI at runtime.
False-positive rules can change in one place while these callers stay put.
Each fingerprint is one file, rule, and line. A new secret on a different line still fails.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants