lawndoc/ggshield workflow log secret scan

Scan workflow run logs for secrets using ggshield

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Maintainedlast commit Nov 17, 2025
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: lawndoc/ggshield-workflow-log-scan@0aace28f3bf271c9d264dcd358b11a4acad828eb # v1

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
discord-webhook-urlDiscord webhook URL to send alertsyes
ggshield-tokenGitGuardian ggshield tokenyes
github-repositoryGitHub repository in the format owner/repono${{ github.repository }}
github-tokenA GitHub PAT used to fetch the workflow logsno${{ github.token }}
workflow-run-attemptAttempt number of the workflow run to scanyes
workflow-run-idRun ID of the workflow to scanyes

no outputs