ci: add secret scanning with gitleaks #305

Closed
nopoz wants to merge 1 commit from nopoz/security/secret-scanning into main
nopoz commented 2026-06-01 08:41:08 +02:00 (Migrated from github.com)

Secret scanning (gitleaks)

What it does: scans the whole Git history on every pull request and push to main for committed credentials (API keys, tokens, private keys).

What it prevents: a secret being committed by mistake, or slipped in by a malicious PR. Complements the already-gitignored .env and data/.

What you'll see: a gitleaks check in the PR's Checks tab. Green = clean.

If it fails: a real credential was likely committed. Treat it as leaked, rotate (regenerate) the key, then remove it from the file.

Cost/noise: runs in ~10s, no secrets or paid license required (uses the gitleaks binary directly, pinned + checksum-verified), free on public repos. Blocking.

## Secret scanning (gitleaks) **What it does:** scans the whole Git history on every pull request and push to `main` for committed credentials (API keys, tokens, private keys). **What it prevents:** a secret being committed by mistake, or slipped in by a malicious PR. Complements the already-gitignored `.env` and `data/`. **What you'll see:** a `gitleaks` check in the PR's Checks tab. Green = clean. **If it fails:** a real credential was likely committed. Treat it as leaked, rotate (regenerate) the key, then remove it from the file. **Cost/noise:** runs in ~10s, no secrets or paid license required (uses the gitleaks binary directly, pinned + checksum-verified), free on public repos. **Blocking.**
sleepy closed this pull request 2026-06-01 19:45:58 +02:00

Pull request closed

Sign in to join this conversation.
No description provided.