GitHub Action
detect-secrets Action
detect-secrets Action is a powerful GitHub Action designed to scan your repository for any secrets that may have been accidentally committed, helping to protect your codebase and minimize the risk of sensitive information leakage. It is built upon the experimental version of slim-detect-secrets
from NASA AMMOS and will be updated to use the official Yelp/detect-secrets version once the customized plugins are merged.
For detailed information about slim/detect-secrets
, please refer to the following links:
- Experimental version of slim-detect-secrets (with additional secret detection plugins)
- SLIM's documentation for detect-secrets usage
To integrate the Detect Secrets Action into your workflow, include the following configuration in your GitHub Actions workflow file:
View the action.yml configuration
The Detect Secrets Action follows these steps to ensure the security of your code:
- Checkout Code: Utilizes GitHub's checkout action to access the repository. This is the code that will be scanned for secrets.
- Install Necessary Packages: Deploys the required Python packages, including the experimental version of
slim-detect-secrets
andjq
. These packages enable the primary functionality of the Action. - Check Existence of .secrets.baseline: Ensures the Action remains operational even if no baseline file exists yet. If the
.secrets.baseline
file is not found, the action creates an initial baseline file by scanning an empty directory. - Scan Repository for Secrets: In this step, the Action backs up the list of known secrets and scans the repository for any new secrets. The scan excludes files starting with '.secrets.' and '.git'. The 'compare_secrets' function is used to identify any differences between the known secrets and newly detected ones. If new secrets are detected, the build fails, and the user is guided to clean up the secrets using the
detect-secrets
tool.
Should you encounter any issues or require further assistance, feel free to create an issue in this repository. We value your feedback and will strive to provide timely support.
We warmly welcome contributions to the Detect Secrets Action. If you have an idea for an improvement or have discovered a bug, please fork this repository, make your changes, and submit a pull request. We appreciate your efforts in helping us make this action better!