From 4b04427c05240f7138ac283723074fb32fd91b23 Mon Sep 17 00:00:00 2001 From: Jithin Date: Tue, 30 Jun 2026 15:21:09 +0530 Subject: [PATCH 1/3] chore: add gitleaks secret-scan workflow and fix .env.example provider vars --- .env.example | 8 ++++---- .github/workflows/secret-scan.yml | 19 +++++++++++++++++++ 2 files changed, 23 insertions(+), 4 deletions(-) create mode 100644 .github/workflows/secret-scan.yml diff --git a/.env.example b/.env.example index 3e857247..28cd555b 100644 --- a/.env.example +++ b/.env.example @@ -17,10 +17,10 @@ # Google Gemini # GOOGLE_GENERATIVE_AI_API_KEY= -# ── OpenAI-compatible endpoints (provider: "other") ─────────────────────────── -# Set a base URL in your opfor config instead of here. API key goes below -# if the endpoint requires one. -# CUSTOM_LLM_API_KEY= +# ── OpenAI-compatible endpoints (provider: "openai-compatible") ─────────────── +# LiteLLM, OpenRouter, Azure, Ollama, etc. Set the base URL in your opfor config; +# put the API key here if the endpoint requires one. +# OPFOR_API_KEY= # ── Telemetry enrichment (optional) ────────────────────────────────────────── diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml new file mode 100644 index 00000000..451a09a0 --- /dev/null +++ b/.github/workflows/secret-scan.yml @@ -0,0 +1,19 @@ +name: Secret Scan + +on: + pull_request: + branches: [master, main] + push: + branches: [master, main] + +jobs: + gitleaks: + name: gitleaks + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + - uses: gitleaks/gitleaks-action@v2 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} From e4098e0871d4271bd0644f8d9f033b15bf146fac Mon Sep 17 00:00:00 2001 From: Jithin Date: Tue, 30 Jun 2026 19:17:17 +0530 Subject: [PATCH 2/3] chore: add gitleaks_license secret to workflow --- .github/workflows/secret-scan.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml index 451a09a0..e258c66c 100644 --- a/.github/workflows/secret-scan.yml +++ b/.github/workflows/secret-scan.yml @@ -17,3 +17,4 @@ jobs: - uses: gitleaks/gitleaks-action@v2 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITLEAKS_LICENSE: ${{ secrets.GITLEAKS_LICENSE }} From 93b42bfa2ca343c4b9b535d62193a97c44012587 Mon Sep 17 00:00:00 2001 From: Jithin Date: Wed, 1 Jul 2026 14:51:35 +0530 Subject: [PATCH 3/3] fix: set persist credentials to false --- .github/workflows/secret-scan.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml index e258c66c..5d2ce21b 100644 --- a/.github/workflows/secret-scan.yml +++ b/.github/workflows/secret-scan.yml @@ -14,6 +14,7 @@ jobs: - uses: actions/checkout@v4 with: fetch-depth: 0 + persist-credentials: false - uses: gitleaks/gitleaks-action@v2 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}