Skip to content

Commit d9def21

Browse files
feat(justfile): add gitleaks secret scanning recipes
Add justfile recipes for running gitleaks secret scanning both on the entire repository and on staged changes. These recipes provide convenient local secret scanning capabilities. - scan-secrets: scan entire repository for secrets - scan-staged: scan only staged changes (matches pre-commit hook)
1 parent aefd2db commit d9def21

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

justfile

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -377,6 +377,16 @@ test-release-all:
377377

378378
## Secrets
379379

380+
# Scan repository for secrets
381+
[group('secrets')]
382+
scan-secrets:
383+
gitleaks detect --verbose --redact
384+
385+
# Scan staged changes for secrets (pre-commit)
386+
[group('secrets')]
387+
scan-staged:
388+
gitleaks protect --staged --verbose --redact
389+
380390
# Show existing secrets using sops
381391
[group('secrets')]
382392
show-secrets:

0 commit comments

Comments
 (0)