Skip to content

feat(security): add gitleaks secret scanning — this repo had none - #47

Merged
hyperpolymath merged 2 commits into
mainfrom
feat/secret-scanning
Aug 24, 2026
Merged

feat(security): add gitleaks secret scanning — this repo had none#47
hyperpolymath merged 2 commits into
mainfrom
feat/secret-scanning

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

An estate-wide audit of secret-scanning coverage found this repository has no leak detection of any kind: no gitleaks, no trufflehog, nothing.

Measured across all 424 repositories: 170 had gitleaks, 73 had gitleaks plus a leftover trufflehog step, 33 had trufflehog only, and 88 — this one among them — had nothing at all.

Adds a caller of the estate's shared secret-scanner reusable, which runs gitleaks over the whole working tree with --no-git and exits non-zero on a finding, alongside its rust-secrets and shell-secrets jobs.

Two details that would fail silently if left out:

  • secrets: inherit is REQUIRED. Without it the gitleaks action's inner secrets.GITHUB_TOKEN is empty and the scan degrades quietly — passing while checking less, which is the failure this campaign exists to remove.
  • Where an actions.lock exists it gains a hand-authored [] entry for this file. gh actions-lock SKIPS reusable-workflow callers, so without it the workflow is rejected as startup_failure with no log and no check run.

Expect findings. A first run on a repository that has never been scanned may surface real secrets, and any it finds have been exposed for as long as they have been committed. Treat a red first run as information, not as a fault in this change — and rotate anything it names rather than only deleting it.

The sweep re-verified from this checkout that no scanner already existed before writing, rather than trusting the audit that selected the repo.

Summary

Closes #

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

How has this been verified?

Checklist

  • My commits are signed (git commit -S).
  • I ran the project's own checks/tests locally and they pass.
  • New files carry the correct SPDX-License-Identifier (code/config MPL-2.0,
    prose CC-BY-SA-4.0); I did not relicense existing files.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole (or I have flagged where I might have).

Notes for reviewers

hyperpolymath and others added 2 commits August 5, 2026 09:41
An estate-wide audit of secret-scanning coverage found this repository has no
leak detection of any kind: no gitleaks, no trufflehog, nothing.

Measured across all 424 repositories: 170 had gitleaks, 73 had gitleaks plus a
leftover trufflehog step, 33 had trufflehog only, and 88 — this one among them
— had nothing at all.

Adds a caller of the estate's shared secret-scanner reusable, which runs
gitleaks over the whole working tree with --no-git and exits non-zero on a
finding, alongside its rust-secrets and shell-secrets jobs.

Two details that would fail silently if left out:

  - `secrets: inherit` is REQUIRED. Without it the gitleaks action's inner
    secrets.GITHUB_TOKEN is empty and the scan degrades quietly — passing
    while checking less, which is the failure this campaign exists to remove.
  - Where an actions.lock exists it gains a hand-authored [] entry for this
    file. gh actions-lock SKIPS reusable-workflow callers, so without it the
    workflow is rejected as startup_failure with no log and no check run.

Expect findings. A first run on a repository that has never been scanned may
surface real secrets, and any it finds have been exposed for as long as they
have been committed. Treat a red first run as information, not as a fault in
this change — and rotate anything it names rather than only deleting it.

The sweep re-verified from this checkout that no scanner already existed
before writing, rather than trusting the audit that selected the repo.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@gitar-bot

gitar-bot Bot commented Aug 24, 2026

Copy link
Copy Markdown

Important

You are using the Gitar free plan. Upgrade to unlock code review, CI analysis, auto-apply, custom automations, and more.

Gitar

@hyperpolymath
hyperpolymath merged commit dc482dd into main Aug 24, 2026
1 check failed
@hyperpolymath
hyperpolymath deleted the feat/secret-scanning branch August 24, 2026 05:21
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant