ci(security): run gitleaks in CI to block committed secrets #163

Merged
gmackie merged 1 commit from ci/gitleaks-secret-scan into main 2026-07-30 05:47:02 +00:00
Owner

Wires gitleaks into CI as a blocking secret scan — the automated enforcement behind the .gitleaks.toml rule added in #161. Closes the gap that let the forgegraph owner DB password sit committed in wrangler.toml (see docs/runbooks/rotate-leaked-owner-credential.md).

What

  • New gitleaks job in ci.yml: downloads the pinned gitleaks binary (v8.30.1) and runs gitleaks dir . -c .gitleaks.toml --redact, failing the build on any finding. Separate job so it gates fast without the pnpm install.
  • Scans the checked-out tree, not full history (history still carries the now-dead leak; retiring it is done — see the runbook).

Config tuning (verified)

Triaged the 36 findings a naive scan produced — all false positives (test fixtures, *.example, docs, vendored Pods/, and ${...} template literals in source). Tuned .gitleaks.toml with path + value allowlists so:

  • Committed tree: 0 findings (scan of git archive HEAD).
  • Real leaks still caught: a wrangler.toml owner cred and an app-source dbcooper cred both flag (regression-tested locally).

Note

pull_request runs use the base branch's workflow, so the gitleaks job first executes post-merge on main; I'll verify that run is green. To make it a required status for merges, add CI / gitleaks to branch protection (separate config).

🤖 Generated with Claude Code

Wires gitleaks into CI as a blocking secret scan — the automated enforcement behind the `.gitleaks.toml` rule added in #161. Closes the gap that let the `forgegraph` owner DB password sit committed in `wrangler.toml` (see `docs/runbooks/rotate-leaked-owner-credential.md`). ## What - New `gitleaks` job in `ci.yml`: downloads the pinned gitleaks binary (v8.30.1) and runs `gitleaks dir . -c .gitleaks.toml --redact`, failing the build on any finding. Separate job so it gates fast without the pnpm install. - Scans the **checked-out tree**, not full history (history still carries the now-dead leak; retiring it is done — see the runbook). ## Config tuning (verified) Triaged the 36 findings a naive scan produced — **all false positives** (test fixtures, `*.example`, docs, vendored `Pods/`, and `${...}` template literals in source). Tuned `.gitleaks.toml` with path + value allowlists so: - **Committed tree: 0 findings** (scan of `git archive HEAD`). - **Real leaks still caught**: a `wrangler.toml` owner cred and an app-source `dbcooper` cred both flag (regression-tested locally). ## Note `pull_request` runs use the base branch's workflow, so the `gitleaks` job first executes **post-merge** on `main`; I'll verify that run is green. To make it a *required* status for merges, add `CI / gitleaks` to branch protection (separate config). 🤖 Generated with [Claude Code](https://claude.com/claude-code)
ci(security): run gitleaks in CI to block committed secrets
All checks were successful
CI / gitleaks (pull_request) Successful in 1m47s
forgegraph/ci CI passed
CI / ci (pull_request) Successful in 7m22s
d6b3e3ba99
Adds a gitleaks job to CI that scans the checked-out tree against .gitleaks.toml
and fails on any finding — closing the gap that let the forgegraph owner DB
password sit committed in wrangler.toml. Tuned the config so the current tree is
clean (0 findings) while real inline DB credentials are still caught: path
allowlists for tests/examples/docs/vendored Pods/.git, and value allowlists for
placeholders, ${...} template literals, localhost DSNs, and KEY_ALG_* consts.
Scans the tree (not full history, which still carries the now-dead leak).
gmackie deleted branch ci/gitleaks-secret-scan 2026-07-30 05:47:02 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
gmackie/ForgeGraph!163
No description provided.