You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ReviewDog Secrets未检测到Terraform密钥,GitHub Action为何不失败?

问题

我在main.tf文件中配置了如下GitHub Provider密钥:

provider "github" {
  token = "jAMQrk2fwYNs" # demo secret - not real don't worry
  organization = "PersonalProjects"
}

同时我的.github/workflows/secret-scanning.yml文件内容如下:

name: Run detect-secrets with reviewdog
run-name: Detect Secrets
on:
  push:
    branches:
      - main

jobs:
  secrets-check:
    runs-on: ubuntu-latest
    name: check for secrets
    steps:
      - uses: actions/checkout@v2
      - name: Run detect-secrets with reviewdog
        uses: reviewdog/action-detect-secrets@v0.11.5

为何我的GitHub Action没有因检测到密钥而失败?

回答
  • reviewdog默认不终止工作流:你使用的reviewdog/action-detect-secrets默认仅会把检测结果以评论形式提交到PR或提交记录中,不会直接触发工作流失败。如果需要让工作流在检测到密钥时终止,必须在action配置中添加fail_on_error: true参数,示例修改如下:
    - name: Run detect-secrets with reviewdog
      uses: reviewdog/action-detect-secrets@v0.11.5
      with:
        fail_on_error: true
    
  • 测试密钥未命中检测规则:你使用的测试密钥jAMQrk2fwYNs不符合detect-secrets内置的GitHub令牌检测格式。GitHub个人访问令牌(PAT)通常带有ghp_、gho_等特定前缀,这个测试值不在工具的识别范围内,因此未被判定为敏感密钥。
  • 缺少扫描范围配置:部分版本的action-detect-secrets需要显式指定扫描范围,若未配置可能遗漏部分文件。可以添加scan_args参数指定扫描整个仓库目录,比如scan_args: "."。

内容的提问来源于stack exchange,提问作者stk1234

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 03:03:08