From 721818193e168c9083b9da711901198170b0c8c5 Mon Sep 17 00:00:00 2001 From: Jory Pestorious Date: Sun, 30 Aug 2026 17:02:02 -0500 Subject: [PATCH] security: add the repository secret-scanning baseline --- .githooks/pre-commit | 14 ++++++++++++++ .github/workflows/security.yml | 25 +++++++++++++++++++++++++ .gitleaks.toml | 5 +++++ .mise.toml | 2 ++ SECURITY.md | 20 ++++++++++++++++++++ 5 files changed, 66 insertions(+) create mode 100755 .githooks/pre-commit create mode 100644 .github/workflows/security.yml create mode 100644 .gitleaks.toml create mode 100644 .mise.toml create mode 100644 SECURITY.md diff --git a/.githooks/pre-commit b/.githooks/pre-commit new file mode 100755 index 0000000..160865a --- /dev/null +++ b/.githooks/pre-commit @@ -0,0 +1,14 @@ +#!/bin/sh +# Enable per clone with: git config core.hooksPath .githooks +set -eu + +if command -v mise >/dev/null 2>&1 && mise which gitleaks >/dev/null 2>&1; then + exec mise exec -- gitleaks git --pre-commit --redact --staged --verbose +fi + +if command -v gitleaks >/dev/null 2>&1; then + exec gitleaks git --pre-commit --redact --staged --verbose +fi + +printf '%s\n' "Gitleaks is required. Run 'mise install' or install Gitleaks 8.30.1." >&2 +exit 1 diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml new file mode 100644 index 0000000..ed4cc8d --- /dev/null +++ b/.github/workflows/security.yml @@ -0,0 +1,25 @@ +name: Security + +on: + push: + pull_request: + workflow_dispatch: + +permissions: + contents: read + +jobs: + secret-scan: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + - name: Scan committed history for secrets + uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e # v3.0.0 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITLEAKS_ENABLE_COMMENTS: "false" + GITLEAKS_ENABLE_SUMMARY: "false" + GITLEAKS_ENABLE_UPLOAD_ARTIFACT: "false" + GITLEAKS_VERSION: "8.30.1" diff --git a/.gitleaks.toml b/.gitleaks.toml new file mode 100644 index 0000000..9c06d1c --- /dev/null +++ b/.gitleaks.toml @@ -0,0 +1,5 @@ +title = "tripod" +minVersion = "8.30.1" + +[extend] +useDefault = true diff --git a/.mise.toml b/.mise.toml new file mode 100644 index 0000000..c422b66 --- /dev/null +++ b/.mise.toml @@ -0,0 +1,2 @@ +[tools] +gitleaks = "8.30.1" diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..692a085 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,20 @@ +# Security policy + +## Supported versions + +Tripod supports the current `main` branch. + +## Report a vulnerability + +Please use [GitHub's private vulnerability reporting](https://github.com/joryeugene/tripod/security/advisories/new) so the report stays private while it is investigated. Do not open a public issue for a suspected vulnerability. + +Include the affected version or commit, reproduction steps, expected impact, and any mitigation you have already tested. Please omit real credentials and sensitive personal data. + +## Local checks + +The native staged secret scan is opt-in: + +```text +mise install +git config core.hooksPath .githooks +```