Latest commit

History

20 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Steadforce SteadOps GitHub workflows

This repository provides GitHub reusable workflows to share between repositories.

Helm hydration workflow

The Helm hydration workflow implements the Helm GitOps hydration pattern. In this context, "hydration" refers to the process of rendering Helm charts into Kubernetes manifests before deployment. This allows you to validate your manifests as part of your CI/CD pipeline, ensuring that only fully rendered and tested resources are applied to your cluster.

Benefits:

  • Enables pre-deployment validation and linting of Kubernetes manifests.
  • Supports customization and templating of resources for different environments.
  • Automates the rendering process, reducing manual errors.

When to use:
Use this workflow when you want to automate the rendering of Helm charts as part of your GitOps pipeline, especially if you need to validate or modify manifests before deployment.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.17.0latestNo
bundle-patches-in-one-prGroup all patch-level subchart updates into a single PR/branch instead of one PR per patch releasetrueNo

Required repository layout:

The calling repository must contain a helm-config.yaml file with the following structure:

releaseName: my-chart # requirednamespace: my-namespace # requiredenvironments:
dev:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-dev.yamlprod:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-prod.yaml

Required permissions:

permissions:
contents: writepull-requests: write

Usage example:

name: Helm hydrationon:
push:
branches:
- mainpermissions:
contents: writepull-requests: writejobs:
hydration:
uses: steadforce/steadops-workflows/.github/workflows/helm-hydration.yaml@main

How it works:

  1. Reads the environment keys from helm-config.yaml and builds a parallel job matrix — one job per environment.
  2. Reads the primary subchart version from Chart.yaml (resolves YAML anchors). If bundle-patches-in-one-pr is true, the patch segment is replaced with x.
  3. For each environment: installs Helm, resolves chart dependencies, runs helm template with the environment-specific value files and API groups, and post-processes CRD manifests to inject ArgoCD ServerSideApply=true and sync-wave -1 annotations.
  4. Ensures the target environments/<name> branch exists on origin (creates an orphan branch if not).
  5. Opens or updates a pull request from hydration-pull-request/<env>-<version> into environments/<env>.

Helm unittest workflow

The helm unittest workflow bundles helm unittest and helm linting.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.19.0latestNo
helm-unittest-versionHelm unittest plugin version, e.g. 1.0.3main (latest)No

Required Secrets:

SecretDescriptionRequired
steadops-helm-renovation-ms-teams-webhookMS Teams webhook URL used for notifications on Renovate branchesYes

Usage example:

name: Helm unittest CIon:
pull_request:
jobs:
unittest:
uses: steadforce/steadops-workflows/.github/workflows/helm-unittest.yaml@mainsecrets:
steadops-helm-renovation-ms-teams-webhook: ${{ secrets.steadops-helm-renovation-ms-teams-webhook }}

How it works:

  1. Installs the requested Helm version and the helm-unittest plugin.
  2. Runs helm dependency update to resolve chart dependencies.
  3. Runs helm unittest and publishes the JUnit test results to the GitHub Actions summary.
  4. Runs helm lint to validate the chart.
  5. On Renovate branches (refs containing renovate/), sends a success or failure notification to MS Teams.

Gitleaks secret scan workflow

Scans the repository for leaked secrets using Gitleaks before they reach the main branch.

Inputs:

InputDescriptionDefaultRequired
gitleaks-ignore-pathPath to the Gitleaks ignore file.gitleaksignoreNo

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
gitleaks:
uses: steadforce/steadops-workflows/.github/workflows/gitleaks.yaml@main

How it works:
Checks out the full git history (fetch-depth: 0) and scans all commits with Gitleaks. Secrets matching patterns in the ignore file are excluded.


Trufflehog secret scan workflow

Scans commits for leaked secrets using Trufflehog OSS. Automatically determines the commit range from the pull request or push event context.

Inputs: None

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
trufflehog:
uses: steadforce/steadops-workflows/.github/workflows/trufflehog-oss.yaml@main

How it works:

  1. Resolves the base/head commit range from the PR or push event. Falls back to HEAD~1 if no valid base is available, and skips the scan if no range can be determined.
  2. Runs Trufflehog over the resolved commit range.
  3. Publishes a results table to the GitHub Actions step summary.
  4. Fails the job if Trufflehog detects any secrets.

About

Workflows to share between repsitories

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

20 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Steadforce SteadOps GitHub workflows

This repository provides GitHub reusable workflows to share between repositories.

Helm hydration workflow

The Helm hydration workflow implements the Helm GitOps hydration pattern. In this context, "hydration" refers to the process of rendering Helm charts into Kubernetes manifests before deployment. This allows you to validate your manifests as part of your CI/CD pipeline, ensuring that only fully rendered and tested resources are applied to your cluster.

Benefits:

  • Enables pre-deployment validation and linting of Kubernetes manifests.
  • Supports customization and templating of resources for different environments.
  • Automates the rendering process, reducing manual errors.

When to use:
Use this workflow when you want to automate the rendering of Helm charts as part of your GitOps pipeline, especially if you need to validate or modify manifests before deployment.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.17.0latestNo
bundle-patches-in-one-prGroup all patch-level subchart updates into a single PR/branch instead of one PR per patch releasetrueNo

Required repository layout:

The calling repository must contain a helm-config.yaml file with the following structure:

releaseName: my-chart # requirednamespace: my-namespace # requiredenvironments:
dev:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-dev.yamlprod:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-prod.yaml

Required permissions:

permissions:
contents: writepull-requests: write

Usage example:

name: Helm hydrationon:
push:
branches:
- mainpermissions:
contents: writepull-requests: writejobs:
hydration:
uses: steadforce/steadops-workflows/.github/workflows/helm-hydration.yaml@main

How it works:

  1. Reads the environment keys from helm-config.yaml and builds a parallel job matrix — one job per environment.
  2. Reads the primary subchart version from Chart.yaml (resolves YAML anchors). If bundle-patches-in-one-pr is true, the patch segment is replaced with x.
  3. For each environment: installs Helm, resolves chart dependencies, runs helm template with the environment-specific value files and API groups, and post-processes CRD manifests to inject ArgoCD ServerSideApply=true and sync-wave -1 annotations.
  4. Ensures the target environments/<name> branch exists on origin (creates an orphan branch if not).
  5. Opens or updates a pull request from hydration-pull-request/<env>-<version> into environments/<env>.

Helm unittest workflow

The helm unittest workflow bundles helm unittest and helm linting.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.19.0latestNo
helm-unittest-versionHelm unittest plugin version, e.g. 1.0.3main (latest)No

Required Secrets:

SecretDescriptionRequired
steadops-helm-renovation-ms-teams-webhookMS Teams webhook URL used for notifications on Renovate branchesYes

Usage example:

name: Helm unittest CIon:
pull_request:
jobs:
unittest:
uses: steadforce/steadops-workflows/.github/workflows/helm-unittest.yaml@mainsecrets:
steadops-helm-renovation-ms-teams-webhook: ${{ secrets.steadops-helm-renovation-ms-teams-webhook }}

How it works:

  1. Installs the requested Helm version and the helm-unittest plugin.
  2. Runs helm dependency update to resolve chart dependencies.
  3. Runs helm unittest and publishes the JUnit test results to the GitHub Actions summary.
  4. Runs helm lint to validate the chart.
  5. On Renovate branches (refs containing renovate/), sends a success or failure notification to MS Teams.

Gitleaks secret scan workflow

Scans the repository for leaked secrets using Gitleaks before they reach the main branch.

Inputs:

InputDescriptionDefaultRequired
gitleaks-ignore-pathPath to the Gitleaks ignore file.gitleaksignoreNo

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
gitleaks:
uses: steadforce/steadops-workflows/.github/workflows/gitleaks.yaml@main

How it works:
Checks out the full git history (fetch-depth: 0) and scans all commits with Gitleaks. Secrets matching patterns in the ignore file are excluded.


Trufflehog secret scan workflow

Scans commits for leaked secrets using Trufflehog OSS. Automatically determines the commit range from the pull request or push event context.

Inputs: None

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
trufflehog:
uses: steadforce/steadops-workflows/.github/workflows/trufflehog-oss.yaml@main

How it works:

  1. Resolves the base/head commit range from the PR or push event. Falls back to HEAD~1 if no valid base is available, and skips the scan if no range can be determined.
  2. Runs Trufflehog over the resolved commit range.
  3. Publishes a results table to the GitHub Actions step summary.
  4. Fails the job if Trufflehog detects any secrets.

About

Workflows to share between repsitories

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

20 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Steadforce SteadOps GitHub workflows

This repository provides GitHub reusable workflows to share between repositories.

Helm hydration workflow

The Helm hydration workflow implements the Helm GitOps hydration pattern. In this context, "hydration" refers to the process of rendering Helm charts into Kubernetes manifests before deployment. This allows you to validate your manifests as part of your CI/CD pipeline, ensuring that only fully rendered and tested resources are applied to your cluster.

Benefits:

  • Enables pre-deployment validation and linting of Kubernetes manifests.
  • Supports customization and templating of resources for different environments.
  • Automates the rendering process, reducing manual errors.

When to use:
Use this workflow when you want to automate the rendering of Helm charts as part of your GitOps pipeline, especially if you need to validate or modify manifests before deployment.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.17.0latestNo
bundle-patches-in-one-prGroup all patch-level subchart updates into a single PR/branch instead of one PR per patch releasetrueNo

Required repository layout:

The calling repository must contain a helm-config.yaml file with the following structure:

releaseName: my-chart # requirednamespace: my-namespace # requiredenvironments:
dev:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-dev.yamlprod:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-prod.yaml

Required permissions:

permissions:
contents: writepull-requests: write

Usage example:

name: Helm hydrationon:
push:
branches:
- mainpermissions:
contents: writepull-requests: writejobs:
hydration:
uses: steadforce/steadops-workflows/.github/workflows/helm-hydration.yaml@main

How it works:

  1. Reads the environment keys from helm-config.yaml and builds a parallel job matrix — one job per environment.
  2. Reads the primary subchart version from Chart.yaml (resolves YAML anchors). If bundle-patches-in-one-pr is true, the patch segment is replaced with x.
  3. For each environment: installs Helm, resolves chart dependencies, runs helm template with the environment-specific value files and API groups, and post-processes CRD manifests to inject ArgoCD ServerSideApply=true and sync-wave -1 annotations.
  4. Ensures the target environments/<name> branch exists on origin (creates an orphan branch if not).
  5. Opens or updates a pull request from hydration-pull-request/<env>-<version> into environments/<env>.

Helm unittest workflow

The helm unittest workflow bundles helm unittest and helm linting.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.19.0latestNo
helm-unittest-versionHelm unittest plugin version, e.g. 1.0.3main (latest)No

Required Secrets:

SecretDescriptionRequired
steadops-helm-renovation-ms-teams-webhookMS Teams webhook URL used for notifications on Renovate branchesYes

Usage example:

name: Helm unittest CIon:
pull_request:
jobs:
unittest:
uses: steadforce/steadops-workflows/.github/workflows/helm-unittest.yaml@mainsecrets:
steadops-helm-renovation-ms-teams-webhook: ${{ secrets.steadops-helm-renovation-ms-teams-webhook }}

How it works:

  1. Installs the requested Helm version and the helm-unittest plugin.
  2. Runs helm dependency update to resolve chart dependencies.
  3. Runs helm unittest and publishes the JUnit test results to the GitHub Actions summary.
  4. Runs helm lint to validate the chart.
  5. On Renovate branches (refs containing renovate/), sends a success or failure notification to MS Teams.

Gitleaks secret scan workflow

Scans the repository for leaked secrets using Gitleaks before they reach the main branch.

Inputs:

InputDescriptionDefaultRequired
gitleaks-ignore-pathPath to the Gitleaks ignore file.gitleaksignoreNo

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
gitleaks:
uses: steadforce/steadops-workflows/.github/workflows/gitleaks.yaml@main

How it works:
Checks out the full git history (fetch-depth: 0) and scans all commits with Gitleaks. Secrets matching patterns in the ignore file are excluded.


Trufflehog secret scan workflow

Scans commits for leaked secrets using Trufflehog OSS. Automatically determines the commit range from the pull request or push event context.

Inputs: None

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
trufflehog:
uses: steadforce/steadops-workflows/.github/workflows/trufflehog-oss.yaml@main

How it works:

  1. Resolves the base/head commit range from the PR or push event. Falls back to HEAD~1 if no valid base is available, and skips the scan if no range can be determined.
  2. Runs Trufflehog over the resolved commit range.
  3. Publishes a results table to the GitHub Actions step summary.
  4. Fails the job if Trufflehog detects any secrets.

About

Workflows to share between repsitories

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

20 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Steadforce SteadOps GitHub workflows

This repository provides GitHub reusable workflows to share between repositories.

Helm hydration workflow

The Helm hydration workflow implements the Helm GitOps hydration pattern. In this context, "hydration" refers to the process of rendering Helm charts into Kubernetes manifests before deployment. This allows you to validate your manifests as part of your CI/CD pipeline, ensuring that only fully rendered and tested resources are applied to your cluster.

Benefits:

  • Enables pre-deployment validation and linting of Kubernetes manifests.
  • Supports customization and templating of resources for different environments.
  • Automates the rendering process, reducing manual errors.

When to use:
Use this workflow when you want to automate the rendering of Helm charts as part of your GitOps pipeline, especially if you need to validate or modify manifests before deployment.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.17.0latestNo
bundle-patches-in-one-prGroup all patch-level subchart updates into a single PR/branch instead of one PR per patch releasetrueNo

Required repository layout:

The calling repository must contain a helm-config.yaml file with the following structure:

releaseName: my-chart # requirednamespace: my-namespace # requiredenvironments:
dev:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-dev.yamlprod:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-prod.yaml

Required permissions:

permissions:
contents: writepull-requests: write

Usage example:

name: Helm hydrationon:
push:
branches:
- mainpermissions:
contents: writepull-requests: writejobs:
hydration:
uses: steadforce/steadops-workflows/.github/workflows/helm-hydration.yaml@main

How it works:

  1. Reads the environment keys from helm-config.yaml and builds a parallel job matrix — one job per environment.
  2. Reads the primary subchart version from Chart.yaml (resolves YAML anchors). If bundle-patches-in-one-pr is true, the patch segment is replaced with x.
  3. For each environment: installs Helm, resolves chart dependencies, runs helm template with the environment-specific value files and API groups, and post-processes CRD manifests to inject ArgoCD ServerSideApply=true and sync-wave -1 annotations.
  4. Ensures the target environments/<name> branch exists on origin (creates an orphan branch if not).
  5. Opens or updates a pull request from hydration-pull-request/<env>-<version> into environments/<env>.

Helm unittest workflow

The helm unittest workflow bundles helm unittest and helm linting.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.19.0latestNo
helm-unittest-versionHelm unittest plugin version, e.g. 1.0.3main (latest)No

Required Secrets:

SecretDescriptionRequired
steadops-helm-renovation-ms-teams-webhookMS Teams webhook URL used for notifications on Renovate branchesYes

Usage example:

name: Helm unittest CIon:
pull_request:
jobs:
unittest:
uses: steadforce/steadops-workflows/.github/workflows/helm-unittest.yaml@mainsecrets:
steadops-helm-renovation-ms-teams-webhook: ${{ secrets.steadops-helm-renovation-ms-teams-webhook }}

How it works:

  1. Installs the requested Helm version and the helm-unittest plugin.
  2. Runs helm dependency update to resolve chart dependencies.
  3. Runs helm unittest and publishes the JUnit test results to the GitHub Actions summary.
  4. Runs helm lint to validate the chart.
  5. On Renovate branches (refs containing renovate/), sends a success or failure notification to MS Teams.

Gitleaks secret scan workflow

Scans the repository for leaked secrets using Gitleaks before they reach the main branch.

Inputs:

InputDescriptionDefaultRequired
gitleaks-ignore-pathPath to the Gitleaks ignore file.gitleaksignoreNo

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
gitleaks:
uses: steadforce/steadops-workflows/.github/workflows/gitleaks.yaml@main

How it works:
Checks out the full git history (fetch-depth: 0) and scans all commits with Gitleaks. Secrets matching patterns in the ignore file are excluded.


Trufflehog secret scan workflow

Scans commits for leaked secrets using Trufflehog OSS. Automatically determines the commit range from the pull request or push event context.

Inputs: None

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
trufflehog:
uses: steadforce/steadops-workflows/.github/workflows/trufflehog-oss.yaml@main

How it works:

  1. Resolves the base/head commit range from the PR or push event. Falls back to HEAD~1 if no valid base is available, and skips the scan if no range can be determined.
  2. Runs Trufflehog over the resolved commit range.
  3. Publishes a results table to the GitHub Actions step summary.
  4. Fails the job if Trufflehog detects any secrets.

About

Workflows to share between repsitories

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

20 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Steadforce SteadOps GitHub workflows

This repository provides GitHub reusable workflows to share between repositories.

Helm hydration workflow

The Helm hydration workflow implements the Helm GitOps hydration pattern. In this context, "hydration" refers to the process of rendering Helm charts into Kubernetes manifests before deployment. This allows you to validate your manifests as part of your CI/CD pipeline, ensuring that only fully rendered and tested resources are applied to your cluster.

Benefits:

  • Enables pre-deployment validation and linting of Kubernetes manifests.
  • Supports customization and templating of resources for different environments.
  • Automates the rendering process, reducing manual errors.

When to use:
Use this workflow when you want to automate the rendering of Helm charts as part of your GitOps pipeline, especially if you need to validate or modify manifests before deployment.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.17.0latestNo
bundle-patches-in-one-prGroup all patch-level subchart updates into a single PR/branch instead of one PR per patch releasetrueNo

Required repository layout:

The calling repository must contain a helm-config.yaml file with the following structure:

releaseName: my-chart # requirednamespace: my-namespace # requiredenvironments:
dev:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-dev.yamlprod:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-prod.yaml

Required permissions:

permissions:
contents: writepull-requests: write

Usage example:

name: Helm hydrationon:
push:
branches:
- mainpermissions:
contents: writepull-requests: writejobs:
hydration:
uses: steadforce/steadops-workflows/.github/workflows/helm-hydration.yaml@main

How it works:

  1. Reads the environment keys from helm-config.yaml and builds a parallel job matrix — one job per environment.
  2. Reads the primary subchart version from Chart.yaml (resolves YAML anchors). If bundle-patches-in-one-pr is true, the patch segment is replaced with x.
  3. For each environment: installs Helm, resolves chart dependencies, runs helm template with the environment-specific value files and API groups, and post-processes CRD manifests to inject ArgoCD ServerSideApply=true and sync-wave -1 annotations.
  4. Ensures the target environments/<name> branch exists on origin (creates an orphan branch if not).
  5. Opens or updates a pull request from hydration-pull-request/<env>-<version> into environments/<env>.

Helm unittest workflow

The helm unittest workflow bundles helm unittest and helm linting.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.19.0latestNo
helm-unittest-versionHelm unittest plugin version, e.g. 1.0.3main (latest)No

Required Secrets:

SecretDescriptionRequired
steadops-helm-renovation-ms-teams-webhookMS Teams webhook URL used for notifications on Renovate branchesYes

Usage example:

name: Helm unittest CIon:
pull_request:
jobs:
unittest:
uses: steadforce/steadops-workflows/.github/workflows/helm-unittest.yaml@mainsecrets:
steadops-helm-renovation-ms-teams-webhook: ${{ secrets.steadops-helm-renovation-ms-teams-webhook }}

How it works:

  1. Installs the requested Helm version and the helm-unittest plugin.
  2. Runs helm dependency update to resolve chart dependencies.
  3. Runs helm unittest and publishes the JUnit test results to the GitHub Actions summary.
  4. Runs helm lint to validate the chart.
  5. On Renovate branches (refs containing renovate/), sends a success or failure notification to MS Teams.

Gitleaks secret scan workflow

Scans the repository for leaked secrets using Gitleaks before they reach the main branch.

Inputs:

InputDescriptionDefaultRequired
gitleaks-ignore-pathPath to the Gitleaks ignore file.gitleaksignoreNo

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
gitleaks:
uses: steadforce/steadops-workflows/.github/workflows/gitleaks.yaml@main

How it works:
Checks out the full git history (fetch-depth: 0) and scans all commits with Gitleaks. Secrets matching patterns in the ignore file are excluded.


Trufflehog secret scan workflow

Scans commits for leaked secrets using Trufflehog OSS. Automatically determines the commit range from the pull request or push event context.

Inputs: None

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
trufflehog:
uses: steadforce/steadops-workflows/.github/workflows/trufflehog-oss.yaml@main

How it works:

  1. Resolves the base/head commit range from the PR or push event. Falls back to HEAD~1 if no valid base is available, and skips the scan if no range can be determined.
  2. Runs Trufflehog over the resolved commit range.
  3. Publishes a results table to the GitHub Actions step summary.
  4. Fails the job if Trufflehog detects any secrets.

About

Workflows to share between repsitories

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

20 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Steadforce SteadOps GitHub workflows

This repository provides GitHub reusable workflows to share between repositories.

Helm hydration workflow

The Helm hydration workflow implements the Helm GitOps hydration pattern. In this context, "hydration" refers to the process of rendering Helm charts into Kubernetes manifests before deployment. This allows you to validate your manifests as part of your CI/CD pipeline, ensuring that only fully rendered and tested resources are applied to your cluster.

Benefits:

  • Enables pre-deployment validation and linting of Kubernetes manifests.
  • Supports customization and templating of resources for different environments.
  • Automates the rendering process, reducing manual errors.

When to use:
Use this workflow when you want to automate the rendering of Helm charts as part of your GitOps pipeline, especially if you need to validate or modify manifests before deployment.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.17.0latestNo
bundle-patches-in-one-prGroup all patch-level subchart updates into a single PR/branch instead of one PR per patch releasetrueNo

Required repository layout:

The calling repository must contain a helm-config.yaml file with the following structure:

releaseName: my-chart # requirednamespace: my-namespace # requiredenvironments:
dev:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-dev.yamlprod:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-prod.yaml

Required permissions:

permissions:
contents: writepull-requests: write

Usage example:

name: Helm hydrationon:
push:
branches:
- mainpermissions:
contents: writepull-requests: writejobs:
hydration:
uses: steadforce/steadops-workflows/.github/workflows/helm-hydration.yaml@main

How it works:

  1. Reads the environment keys from helm-config.yaml and builds a parallel job matrix — one job per environment.
  2. Reads the primary subchart version from Chart.yaml (resolves YAML anchors). If bundle-patches-in-one-pr is true, the patch segment is replaced with x.
  3. For each environment: installs Helm, resolves chart dependencies, runs helm template with the environment-specific value files and API groups, and post-processes CRD manifests to inject ArgoCD ServerSideApply=true and sync-wave -1 annotations.
  4. Ensures the target environments/<name> branch exists on origin (creates an orphan branch if not).
  5. Opens or updates a pull request from hydration-pull-request/<env>-<version> into environments/<env>.

Helm unittest workflow

The helm unittest workflow bundles helm unittest and helm linting.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.19.0latestNo
helm-unittest-versionHelm unittest plugin version, e.g. 1.0.3main (latest)No

Required Secrets:

SecretDescriptionRequired
steadops-helm-renovation-ms-teams-webhookMS Teams webhook URL used for notifications on Renovate branchesYes

Usage example:

name: Helm unittest CIon:
pull_request:
jobs:
unittest:
uses: steadforce/steadops-workflows/.github/workflows/helm-unittest.yaml@mainsecrets:
steadops-helm-renovation-ms-teams-webhook: ${{ secrets.steadops-helm-renovation-ms-teams-webhook }}

How it works:

  1. Installs the requested Helm version and the helm-unittest plugin.
  2. Runs helm dependency update to resolve chart dependencies.
  3. Runs helm unittest and publishes the JUnit test results to the GitHub Actions summary.
  4. Runs helm lint to validate the chart.
  5. On Renovate branches (refs containing renovate/), sends a success or failure notification to MS Teams.

Gitleaks secret scan workflow

Scans the repository for leaked secrets using Gitleaks before they reach the main branch.

Inputs:

InputDescriptionDefaultRequired
gitleaks-ignore-pathPath to the Gitleaks ignore file.gitleaksignoreNo

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
gitleaks:
uses: steadforce/steadops-workflows/.github/workflows/gitleaks.yaml@main

How it works:
Checks out the full git history (fetch-depth: 0) and scans all commits with Gitleaks. Secrets matching patterns in the ignore file are excluded.


Trufflehog secret scan workflow

Scans commits for leaked secrets using Trufflehog OSS. Automatically determines the commit range from the pull request or push event context.

Inputs: None

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
trufflehog:
uses: steadforce/steadops-workflows/.github/workflows/trufflehog-oss.yaml@main

How it works:

  1. Resolves the base/head commit range from the PR or push event. Falls back to HEAD~1 if no valid base is available, and skips the scan if no range can be determined.
  2. Runs Trufflehog over the resolved commit range.
  3. Publishes a results table to the GitHub Actions step summary.
  4. Fails the job if Trufflehog detects any secrets.

About

Workflows to share between repsitories

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

20 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Steadforce SteadOps GitHub workflows

This repository provides GitHub reusable workflows to share between repositories.

Helm hydration workflow

The Helm hydration workflow implements the Helm GitOps hydration pattern. In this context, "hydration" refers to the process of rendering Helm charts into Kubernetes manifests before deployment. This allows you to validate your manifests as part of your CI/CD pipeline, ensuring that only fully rendered and tested resources are applied to your cluster.

Benefits:

  • Enables pre-deployment validation and linting of Kubernetes manifests.
  • Supports customization and templating of resources for different environments.
  • Automates the rendering process, reducing manual errors.

When to use:
Use this workflow when you want to automate the rendering of Helm charts as part of your GitOps pipeline, especially if you need to validate or modify manifests before deployment.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.17.0latestNo
bundle-patches-in-one-prGroup all patch-level subchart updates into a single PR/branch instead of one PR per patch releasetrueNo

Required repository layout:

The calling repository must contain a helm-config.yaml file with the following structure:

releaseName: my-chart # requirednamespace: my-namespace # requiredenvironments:
dev:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-dev.yamlprod:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-prod.yaml

Required permissions:

permissions:
contents: writepull-requests: write

Usage example:

name: Helm hydrationon:
push:
branches:
- mainpermissions:
contents: writepull-requests: writejobs:
hydration:
uses: steadforce/steadops-workflows/.github/workflows/helm-hydration.yaml@main

How it works:

  1. Reads the environment keys from helm-config.yaml and builds a parallel job matrix — one job per environment.
  2. Reads the primary subchart version from Chart.yaml (resolves YAML anchors). If bundle-patches-in-one-pr is true, the patch segment is replaced with x.
  3. For each environment: installs Helm, resolves chart dependencies, runs helm template with the environment-specific value files and API groups, and post-processes CRD manifests to inject ArgoCD ServerSideApply=true and sync-wave -1 annotations.
  4. Ensures the target environments/<name> branch exists on origin (creates an orphan branch if not).
  5. Opens or updates a pull request from hydration-pull-request/<env>-<version> into environments/<env>.

Helm unittest workflow

The helm unittest workflow bundles helm unittest and helm linting.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.19.0latestNo
helm-unittest-versionHelm unittest plugin version, e.g. 1.0.3main (latest)No

Required Secrets:

SecretDescriptionRequired
steadops-helm-renovation-ms-teams-webhookMS Teams webhook URL used for notifications on Renovate branchesYes

Usage example:

name: Helm unittest CIon:
pull_request:
jobs:
unittest:
uses: steadforce/steadops-workflows/.github/workflows/helm-unittest.yaml@mainsecrets:
steadops-helm-renovation-ms-teams-webhook: ${{ secrets.steadops-helm-renovation-ms-teams-webhook }}

How it works:

  1. Installs the requested Helm version and the helm-unittest plugin.
  2. Runs helm dependency update to resolve chart dependencies.
  3. Runs helm unittest and publishes the JUnit test results to the GitHub Actions summary.
  4. Runs helm lint to validate the chart.
  5. On Renovate branches (refs containing renovate/), sends a success or failure notification to MS Teams.

Gitleaks secret scan workflow

Scans the repository for leaked secrets using Gitleaks before they reach the main branch.

Inputs:

InputDescriptionDefaultRequired
gitleaks-ignore-pathPath to the Gitleaks ignore file.gitleaksignoreNo

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
gitleaks:
uses: steadforce/steadops-workflows/.github/workflows/gitleaks.yaml@main

How it works:
Checks out the full git history (fetch-depth: 0) and scans all commits with Gitleaks. Secrets matching patterns in the ignore file are excluded.


Trufflehog secret scan workflow

Scans commits for leaked secrets using Trufflehog OSS. Automatically determines the commit range from the pull request or push event context.

Inputs: None

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
trufflehog:
uses: steadforce/steadops-workflows/.github/workflows/trufflehog-oss.yaml@main

How it works:

  1. Resolves the base/head commit range from the PR or push event. Falls back to HEAD~1 if no valid base is available, and skips the scan if no range can be determined.
  2. Runs Trufflehog over the resolved commit range.
  3. Publishes a results table to the GitHub Actions step summary.
  4. Fails the job if Trufflehog detects any secrets.

About

Workflows to share between repsitories

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

20 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Steadforce SteadOps GitHub workflows

This repository provides GitHub reusable workflows to share between repositories.

Helm hydration workflow

The Helm hydration workflow implements the Helm GitOps hydration pattern. In this context, "hydration" refers to the process of rendering Helm charts into Kubernetes manifests before deployment. This allows you to validate your manifests as part of your CI/CD pipeline, ensuring that only fully rendered and tested resources are applied to your cluster.

Benefits:

  • Enables pre-deployment validation and linting of Kubernetes manifests.
  • Supports customization and templating of resources for different environments.
  • Automates the rendering process, reducing manual errors.

When to use:
Use this workflow when you want to automate the rendering of Helm charts as part of your GitOps pipeline, especially if you need to validate or modify manifests before deployment.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.17.0latestNo
bundle-patches-in-one-prGroup all patch-level subchart updates into a single PR/branch instead of one PR per patch releasetrueNo

Required repository layout:

The calling repository must contain a helm-config.yaml file with the following structure:

releaseName: my-chart # requirednamespace: my-namespace # requiredenvironments:
dev:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-dev.yamlprod:
apis:
- some.crd.io/v1/ResourcevalueFiles:
- values-prod.yaml

Required permissions:

permissions:
contents: writepull-requests: write

Usage example:

name: Helm hydrationon:
push:
branches:
- mainpermissions:
contents: writepull-requests: writejobs:
hydration:
uses: steadforce/steadops-workflows/.github/workflows/helm-hydration.yaml@main

How it works:

  1. Reads the environment keys from helm-config.yaml and builds a parallel job matrix — one job per environment.
  2. Reads the primary subchart version from Chart.yaml (resolves YAML anchors). If bundle-patches-in-one-pr is true, the patch segment is replaced with x.
  3. For each environment: installs Helm, resolves chart dependencies, runs helm template with the environment-specific value files and API groups, and post-processes CRD manifests to inject ArgoCD ServerSideApply=true and sync-wave -1 annotations.
  4. Ensures the target environments/<name> branch exists on origin (creates an orphan branch if not).
  5. Opens or updates a pull request from hydration-pull-request/<env>-<version> into environments/<env>.

Helm unittest workflow

The helm unittest workflow bundles helm unittest and helm linting.

Inputs:

InputDescriptionDefaultRequired
helm-versionHelm CLI version to install, e.g. v3.19.0latestNo
helm-unittest-versionHelm unittest plugin version, e.g. 1.0.3main (latest)No

Required Secrets:

SecretDescriptionRequired
steadops-helm-renovation-ms-teams-webhookMS Teams webhook URL used for notifications on Renovate branchesYes

Usage example:

name: Helm unittest CIon:
pull_request:
jobs:
unittest:
uses: steadforce/steadops-workflows/.github/workflows/helm-unittest.yaml@mainsecrets:
steadops-helm-renovation-ms-teams-webhook: ${{ secrets.steadops-helm-renovation-ms-teams-webhook }}

How it works:

  1. Installs the requested Helm version and the helm-unittest plugin.
  2. Runs helm dependency update to resolve chart dependencies.
  3. Runs helm unittest and publishes the JUnit test results to the GitHub Actions summary.
  4. Runs helm lint to validate the chart.
  5. On Renovate branches (refs containing renovate/), sends a success or failure notification to MS Teams.

Gitleaks secret scan workflow

Scans the repository for leaked secrets using Gitleaks before they reach the main branch.

Inputs:

InputDescriptionDefaultRequired
gitleaks-ignore-pathPath to the Gitleaks ignore file.gitleaksignoreNo

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
gitleaks:
uses: steadforce/steadops-workflows/.github/workflows/gitleaks.yaml@main

How it works:
Checks out the full git history (fetch-depth: 0) and scans all commits with Gitleaks. Secrets matching patterns in the ignore file are excluded.


Trufflehog secret scan workflow

Scans commits for leaked secrets using Trufflehog OSS. Automatically determines the commit range from the pull request or push event context.

Inputs: None

Usage example:

name: Secret scanon:
pull_request:
push:
branches:
- mainjobs:
trufflehog:
uses: steadforce/steadops-workflows/.github/workflows/trufflehog-oss.yaml@main

How it works:

  1. Resolves the base/head commit range from the PR or push event. Falls back to HEAD~1 if no valid base is available, and skips the scan if no range can be determined.
  2. Runs Trufflehog over the resolved commit range.
  3. Publishes a results table to the GitHub Actions step summary.
  4. Fails the job if Trufflehog detects any secrets.

About

Workflows to share between repsitories

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors