Files
light-heart-labs--dreamserver/.github/workflows/secret-scan.yml
T
wehub-resource-sync 9e8f1bbeed
Dashboard / frontend (push) Failing after 0s
Dashboard / api (push) Failing after 0s
Lint PowerShell / powershell-lint (ubuntu-latest) (push) Failing after 1s
Python Lint / Lint Python with Ruff (push) Failing after 1s
ShellCheck / Lint shell scripts (push) Failing after 1s
Matrix Smoke / linux-smoke (push) Failing after 1s
Matrix Smoke / distro: cachyos (push) Failing after 15s
Matrix Smoke / distro: linux-mint-21.3 (push) Failing after 15s
Matrix Smoke / distro: debian-12 (push) Failing after 5m21s
Matrix Smoke / distro: fedora-41 (push) Failing after 4m56s
Matrix Smoke / distro: ubuntu-24.04 (push) Failing after 2m13s
Matrix Smoke / distro: rocky-9 (push) Failing after 10m39s
Matrix Smoke / distro: manjaro (push) Failing after 12m11s
Matrix Smoke / distro: opensuse-tw (push) Failing after 11m53s
Matrix Smoke / distro: archlinux (push) Failing after 20m3s
Matrix Smoke / distro: ubuntu-22.04 (push) Failing after 13m49s
Validate .env Schema / tier-1-env-validation (push) Successful in 52s
Validate .env Schema / tier-2-env-validation (push) Successful in 44s
Validate .env Schema / tier-3-env-validation (push) Successful in 52s
Validate .env Schema / tier-4-env-validation (push) Successful in 51s
Validate Extensions Catalog / Check catalog is up-to-date (push) Failing after 9m47s
Secret Scan / Scan for secrets (push) Failing after 21m4s
Validate Docker Compose / Validate Docker Compose files (push) Has been cancelled
Python Type Check / Type check with mypy (push) Has been cancelled
Validate .env Schema / tier-0-env-validation (push) Has been cancelled
Test Linux / integration-smoke (push) Has been cancelled
Lint PowerShell / powershell-lint (windows-latest) (push) Has been cancelled
Matrix Smoke / macos-smoke (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:31:33 +08:00

57 lines
1.6 KiB
YAML

name: Secret Scan
on:
pull_request:
branches: [main]
push:
branches: [main]
permissions:
contents: read
jobs:
gitleaks:
name: Scan for secrets
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
fetch-depth: 0
# gitleaks-action@v2 now requires a paid license key for GitHub org repos.
# Use the OSS CLI instead to keep secret scanning enabled without paid secrets.
- name: Install gitleaks (OSS)
run: |
set -euo pipefail
VERSION="8.28.0"
ASSET="gitleaks_${VERSION}_linux_x64.tar.gz"
CHECKSUMS="gitleaks_${VERSION}_checksums.txt"
BASE_URL="https://github.com/gitleaks/gitleaks/releases/download/v${VERSION}"
curl -sSLO "${BASE_URL}/${ASSET}"
curl -sSLO "${BASE_URL}/${CHECKSUMS}"
grep " ${ASSET}$" "${CHECKSUMS}" | sha256sum -c -
tar -xzf "${ASSET}" gitleaks
sudo mv gitleaks /usr/local/bin/gitleaks
gitleaks version
- name: Run gitleaks
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
set -euo pipefail
gitleaks detect \
--redact \
--verbose \
--source . \
--report-format json \
--report-path gitleaks-report.json \
--exit-code 1
- name: Upload gitleaks report (always)
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: gitleaks-report
path: gitleaks-report.json
continue-on-error: true