Skip to content

CI: gitleaks secret-scan (BYO-keys trust signal) #13

Description

@ernestprovo23

For a BYO-keys tool whose entire pitch is "never leak keys," a secret-scan step is on-brand, cheap, and a trust signal. mcp-warden already runs gitleaks in CI.

Scope

  • Add a gitleaks GitHub Action on PRs.
  • Config is keys-free by construction, so it should find nothing — this is a guardrail/parity item.

Acceptance

  • gitleaks runs on PRs and reports no secrets.

Source: pre-dev planning audit 2026-06-08 (finding C-4).

Metadata

Metadata

Assignees

No one assigned

    Labels

    ciCI/CD, test infra, lint, secret-scansecurityKey handling, leak prevention, secrets

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions