-
Notifications
You must be signed in to change notification settings - Fork 122
33 lines (28 loc) · 1015 Bytes
/
Copy pathsecrets-scan.yml
File metadata and controls
33 lines (28 loc) · 1015 Bytes
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
name: Secrets Scanning
on:
push:
branches: ['**']
pull_request:
permissions:
contents: read
pull-requests: write
jobs:
gitleaks:
name: Scan for secrets
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
# Use the open-source gitleaks BINARY directly. gitleaks-action@v2 now
# requires a paid GITLEAKS_LICENSE for organizations; the binary itself
# is free (MIT) and performs the same scan.
- name: Install gitleaks
run: |
GITLEAKS_VERSION=8.21.2
curl -sSfL "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" -o gitleaks.tar.gz
tar -xzf gitleaks.tar.gz gitleaks
sudo install -m 0755 gitleaks /usr/local/bin/gitleaks
rm -f gitleaks.tar.gz gitleaks
- name: Scan working tree for secrets
run: gitleaks dir . --config .gitleaks.toml --redact --no-banner --exit-code 1