| name | implementing-secret-scanning-with-gitleaks |
| description | Use when this skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for existing repositories, and remediation workflows for exposed credentials. |
| domain | cybersecurity |
| tags | ["devsecops","cicd","secret-scanning","gitleaks","pre-commit","secure-sdlc"] |
| subdomain | devsecops |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.PS-01","GV.SC-07","ID.IM-04","PR.PS-04"] |
Implementing Secret Scanning With Gitleaks
Overview
Cybersecurity skill for implementing secret scanning with gitleaks. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"implementing secret scanning with gitleaks"
-
"This skill covers implementing Gitleaks for detecting and preventing hardcoded s"
-
When developers may accidentally commit API keys, passwords, tokens, or private keys to repositories
-
When establishing pre-commit gates that prevent secrets from entering the git history
-
When scanning existing repository history for previously committed secrets that need rotation
-
When compliance requirements mandate secret detection across all source code repositories
-
When migrating from manual secret audits to automated continuous scanning
Do not use for detecting secrets in running applications or memory (use runtime secret detection), for managing secrets after detection (use Vault or AWS Secrets Manager), or for scanning container images (use Trivy or Grype).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Gitleaks v8.18+ installed via binary, Go install, or Docker
- Pre-commit framework installed for local hook integration
- Git repository with history to scan
- CI/CD platform access (GitHub Actions, GitLab CI, or equivalent)
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}