# Gitleaks secret-scanning workflow. # # Scans the repository for committed secrets on every push and pull request, # so credentials never land in history unnoticed. It runs on a Forgejo/Gitea # Actions runner; copy it to .github/workflows/ to run it on GitHub Actions too. name: gitleaks on: push: pull_request: jobs: scan: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 with: # Full history — gitleaks needs depth to scan a commit range. fetch-depth: 0 - name: install gitleaks run: | curl -sSL -o gl.tar.gz \ https://github.com/gitleaks/gitleaks/releases/download/v8.21.2/gitleaks_8.21.2_linux_x64.tar.gz tar xzf gl.tar.gz gitleaks chmod +x gitleaks ./gitleaks version - name: scan run: | ./gitleaks detect --source . --no-banner --redact --verbose