{"repo":"duy90utc528/repo-publication-audit","free":true,"listed":false,"github":"https://github.com/duy90utc528/repo-publication-audit","clone":"git clone https://github.com/duy90utc528/repo-publication-audit.git","description":"Dependency-free preflight checks for repositories before making them public","language":"Python","stars":100,"topics":["devtools","open-source","python","secrets-detection","security","github-action","github-actions"],"license":"MIT","category":"security-tools","readme_excerpt":"Repo Publication Audit A small, dependency-free preflight checker for repositories about to become public. It catches common accidental disclosures and reports whether a project has the basic community files expected of an open-source repository. It is intentionally conservative: findings are prompts for review, not proof that a secret is valid or that a repository is safe to publish. Available on the GitHub Marketplace. Quick start After installation, the equivalent command is: For automation, emit machine-readable results: Exclude intentionally committed test data or an exported directory with a repeatable relative path: Respect Git's .gitignore rules, including nested files and negation rules, when Git is installed: CI with GitHub Actions Create .github/workflows/publication-audit.yml in the repository you want to check: Pin to a commit SHA in security-sensitive environments. The action installs the package locally in the GitHub runner; it does not upload repository content. GitHub Code Scanning (SARIF) SARIF is GitHub's standard format for surfacing third-party security findings in Code Scanning. Generate a report, keep the audit non-blocking while it collects findings, then upload it: Configuration Copy .repo-publication-audit.toml.example to .repo-publication-audit.toml in a repository being audited: fail on = \"medium\" also makes absent community files fail CI; \"never\" reports findings without returning a nonzero exit status. The process exits with status 1 when it find","default_branch":null,"files":null,"tree":[],"storefront":"/r/duy90utc528","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/duy90utc528/repo-publication-audit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}