Skip to content

chore(deps)(deps-dev): bump eslint from 10.8.0 to 10.8.1 in /apps/api in the development-dependencies group #526

chore(deps)(deps-dev): bump eslint from 10.8.0 to 10.8.1 in /apps/api in the development-dependencies group

chore(deps)(deps-dev): bump eslint from 10.8.0 to 10.8.1 in /apps/api in the development-dependencies group #526

name: security-secrets
on:
push:
branches: [main]
paths:
- "infra/compose/**"
- ".github/workflows/infra-compose-security-secrets.yml"
pull_request:
branches: [main]
schedule:
- cron: "17 6 * * 1"
concurrency:
group: infra-compose-security-secrets-security-${{ github.ref }}
cancel-in-progress: false
permissions:
contents: read
security-events: write
pull-requests: read
jobs:
gitleaks:
name: gitleaks secret scan
defaults:
run:
working-directory: infra/compose
runs-on: ubuntu-24.04
timeout-minutes: 10
env:
GITLEAKS_VERSION: "8.30.1"
GITLEAKS_SHA256: "551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb"
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Full history so gitleaks can scan every commit.
fetch-depth: 0
- name: Detect relevant changes
uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3
id: filter
with:
filters: |
code:
- 'infra/compose/**'
- '.github/workflows/infra-compose-security-secrets.yml'
- name: Install gitleaks CLI
if: steps.filter.outputs.code == 'true'
run: |
set -euo pipefail
TARBALL="gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"
curl -sSL -o "/tmp/${TARBALL}" \
"https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${TARBALL}"
echo "${GITLEAKS_SHA256} /tmp/${TARBALL}" | sha256sum -c -
tar -xzf "/tmp/${TARBALL}" -C /tmp
sudo mv /tmp/gitleaks /usr/local/bin/
gitleaks version
- name: Scan
if: steps.filter.outputs.code == 'true'
working-directory: ${{ github.workspace }}
run: |
gitleaks detect \
--source . \
--config .gitleaks.toml \
--no-banner \
--redact \
--verbose \
--report-format=sarif \
--report-path=gitleaks-results.sarif \
--exit-code=1
- name: Upload SARIF
if: always()
uses: github/codeql-action/upload-sarif@7c1e4cf0b20d7c1872b26569c00ba908797a59bf # v4
with:
sarif_file: gitleaks-results.sarif
category: gitleaks-compose
continue-on-error: true