keyspoor 0.1.3

Offline secret scanner and Rust library for Git, CI and AI agents, with MCP, JSONL and SARIF
Documentation
# Copy this file to .github/workflows/keyspoor.yml in the repository to scan.
name: Keyspoor

on:
  pull_request:
  push:
  workflow_dispatch:

permissions:
  contents: read

jobs:
  secrets:
    runs-on: ubuntu-latest
    timeout-minutes: 10
    steps:
      - name: Check out source
        uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
        with:
          persist-credentials: false

      - name: Scan checked-out files
        id: scan
        uses: majiayu000/keyspoor@v1
        with:
          path: .
          format: sarif

      - name: Keep redacted report, including failed scans
        if: always() && steps.scan.outputs.report-path != ''
        uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
        with:
          name: keyspoor-report
          path: ${{ steps.scan.outputs.report-path }}
          if-no-files-found: error
          retention-days: 7