{"repo":"GitGuardian/ggshield-action","free":true,"listed":false,"github":"https://github.com/GitGuardian/ggshield-action","clone":"git clone https://github.com/GitGuardian/ggshield-action.git","description":"GitGuardian Shield GitHub Action - Find exposed credentials in your commits","language":null,"stars":349,"topics":["ci","security-tools","devsecops","devops","secrets-detection","gitguardian","github-actions"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"--- GitGuardian Shield GitHub Action Find exposed credentials in your commits using GitGuardian shield . The GitGuardian shield (ggshield) is a CLI application that runs in your local environment or in a CI environment to help you detect more than 400 types of secrets, as well as other potential security vulnerabilities or policy breaks. GitGuardian shield uses our public API through py-gitguardian to scan your files and detect potential secrets or issues in your code. The /v1/scan endpoint of the public API is stateless. We will not store any files you are sending or any secrets we have detected . Requirements - A GitGuardian account. Sign up now if you haven't before! - A GitGuardian API Key. You can create your API Key here . The only required scope is scan . Usage Add a new job to your GitHub workflow using the GitGuardian/ggshield-action action. Add your GitGuardian API Key to the GITGUARDIAN API KEY secret in your project settings. Adding extra options to the action The action accepts the same extra options as the ggshield secret scan ci command. Here is the command reference. Example: Examples of GitGuardian scanning This a sample scan result from GitGuardian shield . If the secret detected has been revoked and you do not wish to rewrite git history, you can use a value of the policy break (for example: the value of password ) or the ignore SHA displayed in your .gitguardian.yaml under matches-ignore . An example configuration file is available here. If there are secre","default_branch":null,"files":null,"tree":[],"storefront":"/r/GitGuardian","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/GitGuardian/ggshield-action/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}