sec(ci): add Gitleaks secret scanner to pipeline
Integrate Gitleaks step in Gitea Actions to automatically detect hardcoded secrets and credentials on every push. Aligns with ISO 27001 traceability and security-by-design requirements.
This commit is contained in:
parent
c2e51ac70d
commit
fae7df9d30
|
|
@ -1,9 +1,10 @@
|
|||
name: Test Runner VPS
|
||||
name: DevSecOps Pipeline - V1 Infrastructure
|
||||
|
||||
on: [push]
|
||||
|
||||
jobs:
|
||||
health-check:
|
||||
name: System & Environment Check
|
||||
runs-on: host
|
||||
steps:
|
||||
- name: System Check
|
||||
|
|
@ -11,3 +12,19 @@ jobs:
|
|||
echo "Pipeline CI/CD opérationnel sur le VPS RYM !"
|
||||
uname -a
|
||||
podman --version
|
||||
|
||||
gitleaks-scan:
|
||||
name: Secret Detection (Gitleaks)
|
||||
runs-on: host
|
||||
steps:
|
||||
- name: Check Out Code
|
||||
uses: actions/checkout@v3
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Run Gitleaks Scan
|
||||
run: |
|
||||
echo "🔍 Lancement du scan Gitleaks..."
|
||||
curl -sSFL https://github.com/gitleaks/gitleaks/releases/download/v8.18.2/gitleaks_8.18.2_linux_x64.tar.gz | tar -xz gitleaks
|
||||
./gitleaks detect --source . -v
|
||||
rm gitleaks
|
||||
|
|
|
|||
Loading…
Reference in New Issue