KeyEnvKeyEnv
SDKs & Integrations

Secret Scanner Action

Scan your codebase for hardcoded secrets in GitHub Actions.

Secret Scanner Action

Scan your codebase for hardcoded secrets before they reach production. This GitHub Action integrates KeyEnv's secret scanning directly into your CI/CD pipeline.

Features

  • Detect API keys, tokens, passwords, and other secrets
  • 149+ patterns covering major providers (AWS, GitHub, Stripe, etc.)
  • Configurable severity thresholds
  • Cross-platform support (Linux, macOS)
  • Optional upload to KeyEnv dashboard
  • JSON output for downstream processing

Basic Usage

Add to your workflow to scan for secrets on every push:

name: Security Scan

on: [push, pull_request]

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Scan for secrets
        uses: keyenv/scan-action@v1

Inputs

InputDescriptionRequiredDefault
severityMinimum severity to fail (critical, high, medium, low)Nomedium
pathPath to scanNo.
uploadUpload results to KeyEnv dashboardNofalse
tokenKeyEnv service token (required if upload is true)No-
versionKeyEnv CLI version to useNolatest

Outputs

OutputDescription
findings-countNumber of secrets found
findings-jsonJSON object containing all findings and summary

Examples

Custom Severity Threshold

Only fail on critical and high severity findings:

- name: Scan for secrets
  uses: keyenv/scan-action@v1
  with:
    severity: high

Scan Specific Directory

Scan only a specific directory:

- name: Scan for secrets
  uses: keyenv/scan-action@v1
  with:
    path: ./src
    severity: medium

Upload to KeyEnv Dashboard

Upload scan results to your KeyEnv dashboard for tracking and reporting:

- name: Scan for secrets
  uses: keyenv/scan-action@v1
  with:
    upload: true
    token: ${{ secrets.KEYENV_TOKEN }}

Use Findings in Subsequent Steps

Access scan results in downstream steps:

- name: Scan for secrets
  id: scan
  uses: keyenv/scan-action@v1
  continue-on-error: true

- name: Process results
  if: steps.scan.outputs.findings-count > 0
  run: |
    echo "Found ${{ steps.scan.outputs.findings-count }} secrets"
    echo "${{ steps.scan.outputs.findings-json }}" | jq '.findings[]'

Pin to Specific CLI Version

Use a specific version of the KeyEnv CLI:

- name: Scan for secrets
  uses: keyenv/scan-action@v1
  with:
    version: v0.5.0

Complete Workflow Example

name: Security

on:
  push:
    branches: [main]
  pull_request:
    branches: [main]

jobs:
  secret-scan:
    name: Secret Scanning
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0  # Full history for better detection

      - name: Scan for secrets
        id: scan
        uses: keyenv/scan-action@v1
        with:
          severity: high
          upload: true
          token: ${{ secrets.KEYENV_TOKEN }}

      - name: Comment on PR
        if: failure() && github.event_name == 'pull_request'
        uses: actions/github-script@v7
        with:
          script: |
            github.rest.issues.createComment({
              issue_number: context.issue.number,
              owner: context.repo.owner,
              repo: context.repo.repo,
              body: '## Secret Scan Failed\n\nSecrets were detected in this PR. Please remove them before merging.\n\nFound: ${{ steps.scan.outputs.findings-count }} secrets'
            })

Severity Levels

  • critical: Highly sensitive secrets (production API keys, private keys)
  • high: Sensitive credentials (database passwords, OAuth tokens)
  • medium: Potentially sensitive data (internal API keys)
  • low: Low-risk findings (generic patterns that may be false positives)

What Gets Detected

The scanner detects secrets from:

CategoryExamples
Cloud ProvidersAWS access keys, GCP service accounts, Azure credentials
Version ControlGitHub PATs, GitLab tokens, Bitbucket app passwords
AI ServicesOpenAI, Anthropic, Google AI API keys
PaymentsStripe, PayPal, Square API keys
CommunicationSlack, Discord, Telegram tokens
DatabasesConnection strings, MongoDB URIs, Redis passwords
InfrastructureTerraform tokens, Kubernetes secrets, SSH keys
GenericJWT tokens, API keys, passwords in URLs

Best Practices

  1. Run on pull requests: Catch secrets before they're merged
  2. Use severity: high: Reduce false positives in CI
  3. Upload results: Track security trends over time
  4. Store tokens securely: Use GitHub Secrets for your KeyEnv token
  5. Block merges: Use required status checks to prevent secret leaks

Difference from keyenv-action

KeyEnv provides two GitHub Actions:

ActionPurpose
keyenv/keyenv-actionFetch secrets - Inject KeyEnv secrets into your workflow
keyenv/scan-actionFind secrets - Scan for hardcoded secrets in your codebase

Use them together for comprehensive secret management:

jobs:
  security:
    runs-on: ubuntu-latest
    steps:
      # First, scan for any hardcoded secrets
      - uses: actions/checkout@v4
      - uses: keyenv/scan-action@v1
        with:
          severity: high

  deploy:
    needs: security
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      # Then, inject managed secrets for deployment
      - uses: keyenv/keyenv-action@v1
        with:
          token: ${{ secrets.KEYENV_TOKEN }}
          environment: production
      - run: ./deploy.sh

On this page