ci(security): run gitleaks in CI to block committed secrets #163
No reviewers
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
gmackie/ForgeGraph!163
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ci/gitleaks-secret-scan"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Wires gitleaks into CI as a blocking secret scan — the automated enforcement behind the
.gitleaks.tomlrule added in #161. Closes the gap that let theforgegraphowner DB password sit committed inwrangler.toml(seedocs/runbooks/rotate-leaked-owner-credential.md).What
gitleaksjob inci.yml: downloads the pinned gitleaks binary (v8.30.1) and runsgitleaks dir . -c .gitleaks.toml --redact, failing the build on any finding. Separate job so it gates fast without the pnpm install.Config tuning (verified)
Triaged the 36 findings a naive scan produced — all false positives (test fixtures,
*.example, docs, vendoredPods/, and${...}template literals in source). Tuned.gitleaks.tomlwith path + value allowlists so:git archive HEAD).wrangler.tomlowner cred and an app-sourcedbcoopercred both flag (regression-tested locally).Note
pull_requestruns use the base branch's workflow, so thegitleaksjob first executes post-merge onmain; I'll verify that run is green. To make it a required status for merges, addCI / gitleaksto branch protection (separate config).🤖 Generated with Claude Code
Adds a gitleaks job to CI that scans the checked-out tree against .gitleaks.toml and fails on any finding — closing the gap that let the forgegraph owner DB password sit committed in wrangler.toml. Tuned the config so the current tree is clean (0 findings) while real inline DB credentials are still caught: path allowlists for tests/examples/docs/vendored Pods/.git, and value allowlists for placeholders, ${...} template literals, localhost DSNs, and KEY_ALG_* consts. Scans the tree (not full history, which still carries the now-dead leak).