{"_id":"@barissozudogru/gha-secrets-audit","name":"@barissozudogru/gha-secrets-audit","dist-tags":{"latest":"0.4.0"},"versions":{"0.4.0":{"name":"@barissozudogru/gha-secrets-audit","version":"0.4.0","description":"Audit GitHub Actions workflows for secret hygiene","type":"module","bin":{"gha-secrets-audit":"dist/cli.js"},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"scripts":{"build":"tsc","prepublishOnly":"npm run build","test":"npm run build && node --test test/*.test.js"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"repository":{"type":"git","url":"git+https://github.com/barissozudogru/gha-secrets-audit.git"},"keywords":["github-actions","secrets","security","audit","devsecops","cli"],"author":{"name":"Baris Sozudogru"},"license":"MIT","devDependencies":{"@types/node":"^25.5.0","typescript":"^5.9.3"},"gitHead":"8dab1a7a8c3644de7784800566a4bac249101a17","_id":"@barissozudogru/gha-secrets-audit@0.4.0","bugs":{"url":"https://github.com/barissozudogru/gha-secrets-audit/issues"},"homepage":"https://github.com/barissozudogru/gha-secrets-audit#readme","_nodeVersion":"25.2.1","_npmVersion":"11.6.2","dist":{"integrity":"sha512-DHJ9G0hHEDw0Z9E+Xlwn3Cpe+GREgPbmp2pEZAxoT6Y+anVuOmETst2kw+Me3lDOjTLIunjawcZdJkNf4L4PPw==","shasum":"cdb74e6824c13d2ea5b6845ee45a391ffbbb93f4","tarball":"https://registry.npmjs.org/@barissozudogru/gha-secrets-audit/-/gha-secrets-audit-0.4.0.tgz","fileCount":9,"unpackedSize":37935,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDjd4NhDuT8NFYtICE+w5IMQZXXrqbk5Em1T6R2eOCsBAIhAK8uh4QOHcCdPC9UvutQCnRYqYVsZ2rl0qaWOz8MRYG/"}]},"_npmUser":{"name":"barissozudogru","email":"barissozudogru@gmail.com"},"directories":{},"maintainers":[{"name":"barissozudogru","email":"barissozudogru@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/gha-secrets-audit_0.4.0_1787176166829_0.14878021437686084"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-19T21:49:26.658Z","0.4.0":"2026-08-19T21:49:26.977Z","modified":"2026-08-19T21:49:27.185Z"},"maintainers":[{"name":"barissozudogru","email":"barissozudogru@gmail.com"}],"description":"Audit GitHub Actions workflows for secret hygiene","homepage":"https://github.com/barissozudogru/gha-secrets-audit#readme","keywords":["github-actions","secrets","security","audit","devsecops","cli"],"repository":{"type":"git","url":"git+https://github.com/barissozudogru/gha-secrets-audit.git"},"author":{"name":"Baris Sozudogru"},"bugs":{"url":"https://github.com/barissozudogru/gha-secrets-audit/issues"},"license":"MIT","readme":"# gha-secrets-audit\n\nStatic analysis tool for GitHub Actions workflow files to inspect secret usage and detect hygiene issues. It runs entirely offline without reading secret values or making network calls.\n\n\n## Quick Start\n\n```bash\n# Run without installing\nnpx @barissozudogru/gha-secrets-audit\n\n# Or install globally\nnpm install -g @barissozudogru/gha-secrets-audit\n```\n\n## Detection Rules\n\nThe scanner maps every secret reference across workflow files by file, job, step, and line number, checking for:\n\n- **Over-exposed secrets**: Credentials referenced in 3 or more jobs (configurable via `--threshold`), violating least-privilege design.\n- **If-condition leaks**: Secrets referenced inside `if:` conditions, which GitHub Actions evaluates and prints in workflow execution logs.\n- **Duplicate secret patterns**: Near-duplicate or base-name matched secret names that suggest credential duplication or inconsistent naming conventions.\n\n\n## Usage\n\n```bash\n# Scan .github/workflows/ in the current directory\ngha-secrets-audit\n\n# Scan a specific workflows directory\ngha-secrets-audit --path /path/to/repo/.github/workflows\n\n# Output JSON for downstream tooling\ngha-secrets-audit --json\n\n# Exit with code 1 if any findings are detected (CI enforcement)\ngha-secrets-audit --strict\n\n# Raise the over-exposure threshold to 5 jobs\ngha-secrets-audit --threshold 5\n\n# Exclude specific secrets from all findings\ngha-secrets-audit --exclude GITHUB_TOKEN,NPM_TOKEN\n\n# Combine flags\ngha-secrets-audit --path ./workflows --threshold 5 --exclude GITHUB_TOKEN --strict\n```\n\n## Options\n\n| Flag | Alias | Default | Description |\n|------|-------|---------|-------------|\n| `--path <dir>` | `-p` | `.github/workflows` | Path to the workflows directory to scan |\n| `--json` | | `false` | Output results as JSON instead of human-readable text |\n| `--strict` | | `false` | Exit with code `1` if any finding is detected |\n| `--threshold <n>` | `-t` | `3` | Minimum number of jobs a secret must appear in to be flagged as over-exposed |\n| `--exclude <names>` | `-e` | | Comma-separated list of secret names to omit from all findings |\n| `--version` | `-v` | | Print the installed version |\n| `--help` | `-h` | | Show help text |\n\n## Example Output\n\n```\ngha-secrets-audit\nScanning: /repo/.github/workflows\n------------------------------------------------------------------------\n\nREFERENCED SECRETS\n  SECRET NAME              REFS  JOBS  FILES  NOTE\n  -------------------------------------------------------\n  AWS_ACCESS_KEY_ID           5     5      3\n  AWS_SECRET_ACCESS_KEY       5     5      3\n  DEPLOY_SSH_KEY              2     2      1\n  GITHUB_TOKEN                3     3      2  (standard)\n  NPM_TOKEN                   1     1      1\n  SLACK_WEBHOOK               4     4      2\n\nOVER-EXPOSED SECRETS\nSecrets used in 3+ jobs may violate least-privilege principle\n\n  AWS_ACCESS_KEY_ID\n  Referenced in 5 job(s) across 3 file(s)\n  Secret \"AWS_ACCESS_KEY_ID\" is referenced in 5 jobs across 3 workflow(s).\n  Consider scoping it to only the jobs that require it, or splitting into\n  more specific secrets per integration.\n    deploy.yml\n      build / step-1 (line 34)\n      publish / step-2 (line 67)\n    release.yml\n      release / step-1 (line 22)\n\n  SLACK_WEBHOOK\n  Referenced in 4 job(s) across 2 file(s)\n  ...\n\nIF-CONDITION SECRET USAGE\n\n  AWS_SECRET_ACCESS_KEY\n  deploy.yml - job: validate, line 41\n  Condition: ${{ secrets.AWS_SECRET_ACCESS_KEY != '' }}\n  Warning: secret values used in if: conditions are visible in GitHub Actions logs.\n\nDUPLICATE PATTERNS\nSecrets with similar names may be redundant or inconsistently named\n\n  [AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY]\n  These secrets share the base name \"AWS\" and may represent the same\n  credential under different naming conventions, or could be consolidated.\n\nHYGIENE SUMMARY\n\n  Workflows scanned  : 3\n  Unique secrets     : 6\n  GITHUB_TOKEN refs  : 3\n  Over-exposed       : 2\n  Duplicate groups   : 1\n  if: cond. warnings : 1\n\n  Recommendations\n  ! Review 2 over-exposed secret(s) and restrict their scope to only the jobs that require them.\n  ! Investigate 1 potential duplicate secret group(s) to reduce credential sprawl.\n  ! 1 secret(s) used in \"if:\" conditions - these values may be exposed in GitHub Actions logs.\n\n------------------------------------------------------------------------\n```\n\n## CI Integration\n\nAdd the audit step to your pull request workflow to enforce secret hygiene on every PR:\n\n```yaml\nname: Security\n\non:\n  pull_request:\n\njobs:\n  secret-hygiene:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n\n      - name: Audit secrets hygiene\n        run: npx @barissozudogru/gha-secrets-audit --strict\n```\n\nWith `--strict`, the job exits `1` and blocks the PR merge if any over-exposed secrets, duplicate groups, or if-condition warnings are detected.\n\nTo exclude known-acceptable secrets from the check:\n\n```yaml\n- name: Audit secrets hygiene\n  run: npx @barissozudogru/gha-secrets-audit --strict --exclude GITHUB_TOKEN\n```\n\n## Exit Codes\n\n| Code | Condition |\n|------|-----------|\n| `0` | Scan completed successfully with no findings, or `--strict` was not set |\n| `1` | `--strict` is set and at least one finding was detected (over-exposed secret, duplicate group, or if-condition warning) |\n| `1` | Fatal error: unreadable path, invalid argument, or filesystem failure |\n\n## License\n\n[MIT](LICENSE)\n","readmeFilename":"README.md","_rev":"1-e7a7737b98f1947c91a05049f528cebc"}