missionwired/Detect Secrets Scanner

Scan for VERIFIED hardcoded secrets and upload to GitHub Code Scanning.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Maintainedlast commit Nov 6, 2025
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: missionwired/secret-scanner-action@b939b4154bc606f33abe79fdaf8edaf5b347d433 # v1

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
scan-pathDirectory to scan for secrets (e.g., ./src/.aws-sam/build)no.
upload-sarifUpload SARIF results to GitHub Code Scanningnofalse
fail-on-detectionFail workflow if verified secrets detectednotrue
debug-modeEnable verbose diagnostic loggingnofalse

no outputs