ci(gitleaks): add secret-scan workflow (BYO-keys trust signal)#26
Merged
Conversation
Uses gitleaks/gitleaks-action@v2 with full history fetch (fetch-depth=0) to scan for leaked secrets. Hard-fail check — this is the BYO-keys trust signal: conclave reads keys from env vars only and this gate enforces that no credentials ever land in the tree.
gitleaks-action@v2 calls the GitHub API to list PR commits but requires pull_requests=read which the default token doesn't grant without an explicit permissions block. v3 also resolves the Node.js 20 deprecation warning.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
.github/workflows/gitleaks.ymltriggered on push tomainand all PRsgitleaks/gitleaks-action@v2withfetch-depth: 0for full history scangitleakscheck to fail, blocking mergeWhy this matters
Conclave is a BYO-keys tool — keys are read from env vars and never stored. The
gitleaks scan is the headline trust signal for public users and contributors that
no credentials can land in the tree undetected.
Test plan
gitleakscheck passes (clean repo — no secrets in history or working tree)pytestandruffchecks still pass