9e8f1bbeed
Dashboard / frontend (push) Failing after 0s
Dashboard / api (push) Failing after 0s
Lint PowerShell / powershell-lint (ubuntu-latest) (push) Failing after 1s
Python Lint / Lint Python with Ruff (push) Failing after 1s
ShellCheck / Lint shell scripts (push) Failing after 1s
Matrix Smoke / linux-smoke (push) Failing after 1s
Matrix Smoke / distro: cachyos (push) Failing after 15s
Matrix Smoke / distro: linux-mint-21.3 (push) Failing after 15s
Matrix Smoke / distro: debian-12 (push) Failing after 5m21s
Matrix Smoke / distro: fedora-41 (push) Failing after 4m56s
Matrix Smoke / distro: ubuntu-24.04 (push) Failing after 2m13s
Matrix Smoke / distro: rocky-9 (push) Failing after 10m39s
Matrix Smoke / distro: manjaro (push) Failing after 12m11s
Matrix Smoke / distro: opensuse-tw (push) Failing after 11m53s
Matrix Smoke / distro: archlinux (push) Failing after 20m3s
Matrix Smoke / distro: ubuntu-22.04 (push) Failing after 13m49s
Validate .env Schema / tier-1-env-validation (push) Successful in 52s
Validate .env Schema / tier-2-env-validation (push) Successful in 44s
Validate .env Schema / tier-3-env-validation (push) Successful in 52s
Validate .env Schema / tier-4-env-validation (push) Successful in 51s
Validate Extensions Catalog / Check catalog is up-to-date (push) Failing after 9m47s
Secret Scan / Scan for secrets (push) Failing after 21m4s
Validate Docker Compose / Validate Docker Compose files (push) Has been cancelled
Python Type Check / Type check with mypy (push) Has been cancelled
Validate .env Schema / tier-0-env-validation (push) Has been cancelled
Test Linux / integration-smoke (push) Has been cancelled
Lint PowerShell / powershell-lint (windows-latest) (push) Has been cancelled
Matrix Smoke / macos-smoke (push) Has been cancelled
57 lines
1.6 KiB
YAML
57 lines
1.6 KiB
YAML
name: Secret Scan
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
push:
|
|
branches: [main]
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
gitleaks:
|
|
name: Scan for secrets
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
# gitleaks-action@v2 now requires a paid license key for GitHub org repos.
|
|
# Use the OSS CLI instead to keep secret scanning enabled without paid secrets.
|
|
- name: Install gitleaks (OSS)
|
|
run: |
|
|
set -euo pipefail
|
|
VERSION="8.28.0"
|
|
ASSET="gitleaks_${VERSION}_linux_x64.tar.gz"
|
|
CHECKSUMS="gitleaks_${VERSION}_checksums.txt"
|
|
BASE_URL="https://github.com/gitleaks/gitleaks/releases/download/v${VERSION}"
|
|
curl -sSLO "${BASE_URL}/${ASSET}"
|
|
curl -sSLO "${BASE_URL}/${CHECKSUMS}"
|
|
grep " ${ASSET}$" "${CHECKSUMS}" | sha256sum -c -
|
|
tar -xzf "${ASSET}" gitleaks
|
|
sudo mv gitleaks /usr/local/bin/gitleaks
|
|
gitleaks version
|
|
|
|
- name: Run gitleaks
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: |
|
|
set -euo pipefail
|
|
gitleaks detect \
|
|
--redact \
|
|
--verbose \
|
|
--source . \
|
|
--report-format json \
|
|
--report-path gitleaks-report.json \
|
|
--exit-code 1
|
|
|
|
- name: Upload gitleaks report (always)
|
|
if: always()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
|
|
with:
|
|
name: gitleaks-report
|
|
path: gitleaks-report.json
|
|
continue-on-error: true
|