Skip to content

Commit ec530a5

Browse files
feat(ci): remove GitGuardian API key from secrets management
Remove GITGUARDIAN_API_KEY from ghsecrets recipe and check-secrets pattern since we've migrated to open-source gitleaks for secret scanning.
1 parent 420f9f6 commit ec530a5

File tree

1 file changed

+1
-2
lines changed

1 file changed

+1
-2
lines changed

justfile

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,6 @@ ghsecrets repo="":
8585
echo
8686
sops exec-env vars/shared.yaml '\
8787
gh secret set CACHIX_AUTH_TOKEN --repo='"$REPO"' --body="$CACHIX_AUTH_TOKEN" && \
88-
gh secret set GITGUARDIAN_API_KEY --repo='"$REPO"' --body="$GITGUARDIAN_API_KEY" && \
8988
gh secret set CLOUDFLARE_ACCOUNT_ID --repo='"$REPO"' --body="$CLOUDFLARE_ACCOUNT_ID" && \
9089
gh secret set CLOUDFLARE_API_TOKEN --repo='"$REPO"' --body="$CLOUDFLARE_API_TOKEN"'
9190
echo
@@ -420,7 +419,7 @@ run-with-secrets +command:
420419
[group('secrets')]
421420
check-secrets:
422421
@printf "Check sops environment for secrets\n\n"
423-
@sops exec-env vars/shared.yaml 'env | grep -E "GITHUB|CACHIX|CLOUDFLARE|GITGUARDIAN" | sed "s/=.*$/=***REDACTED***/"'
422+
@sops exec-env vars/shared.yaml 'env | grep -E "GITHUB|CACHIX|CLOUDFLARE" | sed "s/=.*$/=***REDACTED***/"'
424423

425424
# Show specific secret value from shared secrets
426425
[group('secrets')]

0 commit comments

Comments
 (0)