# gitleaks secret-scan workflow. # # Scans the repository for accidentally committed secrets (API keys, tokens, # private keys) on every push and pull request. # # This is a Forgejo/Gitea Actions workflow; it is a no-op if no Actions runner # is configured, and is safe to delete if you do not use Forgejo/Gitea Actions. name: gitleaks on: push: pull_request: jobs: scan: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 with: # Full history — gitleaks needs depth to scan a commit range. fetch-depth: 0 - name: install gitleaks run: | curl -sSL -o gl.tar.gz \ https://github.com/gitleaks/gitleaks/releases/download/v8.21.2/gitleaks_8.21.2_linux_x64.tar.gz tar xzf gl.tar.gz gitleaks chmod +x gitleaks ./gitleaks version - name: scan run: | ./gitleaks detect --source . --no-banner --redact --verbose