Detects secrets that are defined in the repository and are not used in Github Actions
Project description
detect-gh-actions-unused-secrets
Detects secrets that are defined in the repository and are not used in Github Actions.
What it does:
- Get repository secrets using Github Actions API
- Clone the repository
- Search through the Github Actions related files (
.github/workflows/*.yaml
and.github/workflows/*.yml
) and try to find usages of each secret - Report those secrets which are not found
Prerequisites
- Github token with
repo
scope (Github docs)
Example
pip install detect-gh-actions-unused-secrets
detect-gh-actions-unused-secrets <token> <owner>/<repo1> <owner/repo2>
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Close
Hashes for detect_gh_actions_unused_secrets-0.3.0.tar.gz
Algorithm | Hash digest | |
---|---|---|
SHA256 | e05e3f76844304e9c9b4836b3633ec3e528e4a281a655bdc1a6efa67faf153d0 |
|
MD5 | a485336cc2fc789a8485503c6d3f9d1c |
|
BLAKE2b-256 | 4cdea19bac4abc9374bd6aa2fe3b6dda24396a6fa83120277eee9c9295f831be |
Close
Hashes for detect_gh_actions_unused_secrets-0.3.0-py2.py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | ad23293a3c6dfe9dd974aee32dcba69ee7bb7410e90ffff734d2a09743455919 |
|
MD5 | 80c084881daa6668601ad5b303f302c8 |
|
BLAKE2b-256 | 1e0faa583e59bdda8fd7f768028f782ab837aa5300d7b9180a807708007844c5 |