name: Secret scan on: pull_request: push: permissions: contents: read jobs: secret-scan: name: Secret scan (gitleaks) runs-on: ubuntu-latest timeout-minutes: 10 steps: - uses: actions/checkout@v4 with: fetch-depth: 0 - name: Compute scan range (diff of new commits only) id: range run: | if [ "$GITHUB_EVENT_NAME" = "pull_request" ]; then RANGE="${{ github.event.pull_request.base.sha }}...${{ github.event.pull_request.head.sha }}" else BEFORE="${{ github.event.before }}" if [ "$BEFORE" = "0000000000000000000000000000000000000000" ]; then RANGE="$(git rev-list --max-parents=0 HEAD | tail -1)..$GITHUB_SHA" else RANGE="$BEFORE..$GITHUB_SHA" fi fi echo "RANGE=$RANGE" >> "$GITHUB_ENV" echo "Scanning range: $RANGE" - name: Gitleaks (diff-only, fail on leak) env: GITLEAKS_RANGE: ${{ env.RANGE }} run: | set -euo pipefail # install the gitleaks binary (linux-amd64) instead of a docker action: # the docker://zricethezav/gitleaks action hardcodes /github/workspace, # which does not exist on the Gitea (act) runner. $GITHUB_WORKSPACE is the # checkout dir on BOTH runners (GitHub and Gitea act). curl -fsSLo /tmp/gitleaks.tar.gz \ https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz tar -xzf /tmp/gitleaks.tar.gz -C /tmp gitleaks chmod +x /tmp/gitleaks /tmp/gitleaks detect \ --source "$GITHUB_WORKSPACE" \ --log-opts="$GITLEAKS_RANGE" \ --redact \ --verbose