Skip to content

fix: close code-scanning alerts #12

fix: close code-scanning alerts

fix: close code-scanning alerts #12

name: security-secrets
on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
- cron: '17 6 * * 1'
concurrency:
group: security-secrets-${{ github.ref }}
cancel-in-progress: false
permissions:
contents: read
jobs:
gitleaks:
name: gitleaks secret scan
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
contents: read
security-events: write
pull-requests: read
env:
GITLEAKS_VERSION: '8.30.1'
GITLEAKS_SHA256: '551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb'
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: Install gitleaks CLI
run: |
set -euo pipefail
TARBALL="gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"
curl -sSL -o "/tmp/${TARBALL}" \
"https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${TARBALL}"
echo "${GITLEAKS_SHA256} /tmp/${TARBALL}" | sha256sum -c -
tar -xzf "/tmp/${TARBALL}" -C /tmp
sudo mv /tmp/gitleaks /usr/local/bin/
gitleaks version
- name: Scan
run: |
gitleaks detect \
--source . \
--config .gitleaks.toml \
--no-banner \
--redact \
--verbose \
--report-format=sarif \
--report-path=gitleaks-results.sarif \
--exit-code=1
- name: Upload SARIF
if: always()
uses: github/codeql-action/upload-sarif@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8
with:
sarif_file: gitleaks-results.sarif
category: gitleaks
continue-on-error: true