Skip to content

Release 2026-09-03b: CI secret-history scan fix, dependency refresh (… #35

Release 2026-09-03b: CI secret-history scan fix, dependency refresh (…

Release 2026-09-03b: CI secret-history scan fix, dependency refresh (… #35

Workflow file for this run

name: Secret Scanning
on:
push:
branches: [ main, master, develop ]
pull_request:
branches: [ main, master, develop ]
jobs:
secret-scan:
name: Detect Secrets
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
fetch-depth: 0 # Full history for comprehensive scanning
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Install detect-secrets
run: |
pip install detect-secrets
- name: Run detect-secrets scan
run: |
detect-secrets scan \
--exclude-files 'configs/.*\.json' \
--exclude-files '\.md$' \
--exclude-files 'package-lock\.json' \
--exclude-files '\.lock$' \
--exclude-files '\.baseline$' \
--baseline .secrets.baseline
- name: Check for secrets in git history (last 100 commits)
run: |
# detect-secrets 1.5 has no stdin mode, so the recent history is written to a
# file first. Baseline files, lock files and markdown are left out of the diff;
# a finding whose hash is already in .secrets.baseline is a known placeholder.
git log --all --pretty=format: -p -100 -- . ':!*.baseline' ':!*.lock' ':!*.md' > history.diff
detect-secrets scan --exclude-files 'configs/.*\.json' history.diff > history-scan.json
python - history-scan.json <<'PY'
import json, sys
known = {f.get("hashed_secret")
for fs in json.load(open(".secrets.baseline")).get("results", {}).values()
for f in fs}
results = json.load(open(sys.argv[1])).get("results", {})
new = [(p, f.get("line_number"), f.get("type"))
for p, fs in results.items() for f in fs
if f.get("hashed_secret") not in known]
for path, line, kind in new:
print(f"{path}:{line} {kind}")
if new:
sys.exit("Secrets detected in git history that are not in the baseline")
print("No new secrets detected in git history")
PY
- name: Security scan summary
if: always()
run: |
echo "✅ Secret scanning complete"
echo "If secrets were detected, the job will fail above"
echo "To update baseline: detect-secrets scan --baseline .secrets.baseline"