Skip to content

Conversation

@skeller-exy
Copy link
Collaborator

@skeller-exy skeller-exy commented Sep 10, 2025

This issue addresses part of https://app.zenhub.com/workspaces/bloom-5dc32d7144bd400001315dac/issues/gh/bloom-housing/bloom/5358

This adds a github action which will alert on pushes that contain patterns matching secrets, keys, tokens, etc. If any secrets are found a comment will be added in the PR to rotate it. See results from test secrets below.

Screenshot 2025-09-11 at 12 23 07 PM

The comments below were to test if it would work on pr comments as well. It looks like for this to be a valid test the action may need to be on the main branch. I will test again after merge.

@skeller-exy
Copy link
Collaborator Author

Test fake secret in comment: AKIAQYLPMN5HHHFPZAM2

@skeller-exy skeller-exy marked this pull request as ready for review September 10, 2025 17:51
@skeller-exy
Copy link
Collaborator Author

Test again AKIAQYLPMN5HHHFPZAM2

@skeller-exy skeller-exy merged commit d0f2d24 into main Sep 12, 2025
2 checks passed
@skeller-exy skeller-exy deleted the bloom-5358/add-gitleaks-action branch September 12, 2025 13:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants