diff --git a/.githooks/pre-commit b/.githooks/pre-commit new file mode 100755 index 0000000..160865a --- /dev/null +++ b/.githooks/pre-commit @@ -0,0 +1,14 @@ +#!/bin/sh +# Enable per clone with: git config core.hooksPath .githooks +set -eu + +if command -v mise >/dev/null 2>&1 && mise which gitleaks >/dev/null 2>&1; then + exec mise exec -- gitleaks git --pre-commit --redact --staged --verbose +fi + +if command -v gitleaks >/dev/null 2>&1; then + exec gitleaks git --pre-commit --redact --staged --verbose +fi + +printf '%s\n' "Gitleaks is required. Run 'mise install' or install Gitleaks 8.30.1." >&2 +exit 1 diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml new file mode 100644 index 0000000..ed4cc8d --- /dev/null +++ b/.github/workflows/security.yml @@ -0,0 +1,25 @@ +name: Security + +on: + push: + pull_request: + workflow_dispatch: + +permissions: + contents: read + +jobs: + secret-scan: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + - name: Scan committed history for secrets + uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e # v3.0.0 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITLEAKS_ENABLE_COMMENTS: "false" + GITLEAKS_ENABLE_SUMMARY: "false" + GITLEAKS_ENABLE_UPLOAD_ARTIFACT: "false" + GITLEAKS_VERSION: "8.30.1" diff --git a/.gitleaks.toml b/.gitleaks.toml new file mode 100644 index 0000000..9c06d1c --- /dev/null +++ b/.gitleaks.toml @@ -0,0 +1,5 @@ +title = "tripod" +minVersion = "8.30.1" + +[extend] +useDefault = true diff --git a/.mise.toml b/.mise.toml new file mode 100644 index 0000000..c422b66 --- /dev/null +++ b/.mise.toml @@ -0,0 +1,2 @@ +[tools] +gitleaks = "8.30.1" diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..692a085 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,20 @@ +# Security policy + +## Supported versions + +Tripod supports the current `main` branch. + +## Report a vulnerability + +Please use [GitHub's private vulnerability reporting](https://github.com/joryeugene/tripod/security/advisories/new) so the report stays private while it is investigated. Do not open a public issue for a suspected vulnerability. + +Include the affected version or commit, reproduction steps, expected impact, and any mitigation you have already tested. Please omit real credentials and sensitive personal data. + +## Local checks + +The native staged secret scan is opt-in: + +```text +mise install +git config core.hooksPath .githooks +```