ci: CI-gate gitleaks (scan secrets au push)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,17 @@
|
||||
name: Gitleaks (secret scan)
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
workflow_dispatch: {}
|
||||
jobs:
|
||||
gitleaks:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
- name: Secret scan (gitleaks)
|
||||
run: |
|
||||
set -e
|
||||
curl -fsSL https://github.com/gitleaks/gitleaks/releases/download/v8.18.4/gitleaks_8.18.4_linux_x64.tar.gz | tar xz gitleaks
|
||||
./gitleaks detect --source . -c .gitleaks.toml --no-git --redact --no-banner --exit-code 1
|
||||
echo "✓ aucun secret détecté"
|
||||
@@ -0,0 +1,27 @@
|
||||
title = "homelab"
|
||||
[extend]
|
||||
useDefault = true
|
||||
[[rules]]
|
||||
id = "groq-key"
|
||||
description = "Groq API key"
|
||||
regex = '''gsk_[A-Za-z0-9]{20,}'''
|
||||
[[rules]]
|
||||
id = "plane-key"
|
||||
description = "Plane API key"
|
||||
regex = '''plane_api_[A-Za-z0-9]{10,}'''
|
||||
[[rules]]
|
||||
id = "vault-token"
|
||||
description = "Vault token"
|
||||
regex = '''hvs\.[A-Za-z0-9_-]{15,}'''
|
||||
[[rules]]
|
||||
id = "hex40-token-ctx"
|
||||
description = "40-hex token in credential context (Gitea etc.)"
|
||||
regex = '''(?i)(?:tok|token|secret|key|auth|bearer|pass|pwd)['"=: ]{0,12}([a-f0-9]{40})'''
|
||||
[allowlist]
|
||||
description = "vendored / lock / build artifacts"
|
||||
paths = [
|
||||
'''.*\.min\.(js|css)$''',
|
||||
'''.*-lock\.json$''',
|
||||
'''.*\.lock$''',
|
||||
'''(^|/)(vendor|dist|node_modules|build|three\.min|mermaid\.min)''',
|
||||
]
|
||||
Reference in New Issue
Block a user