Repository navigation
logscrub --check FILE... writes nothing and exits 1 if anything would be masked, 0 if the files are clean, 2 on a usage error and 3 on a read or scan error. Use it as a gate before logs, artifacts or support bundles are published.
logscrub --check build.log || { echo "secrets or personal data in build.log"; exit 1; }- uses: hbenali/logscrub@1.1.0 # pin an exact release (or a commit SHA)
with:
files: build.log logs/*.log # spaces or newlines; globs are expanded
args: --config .github/logscrub.toml
sarif-file: logscrub.sarif # optional: also write a SARIF report
- uses: github/codeql-action/upload-sarif@v4
if: always()
with:
sarif_file: logscrub.sarifThe action downloads the release archive for the runner (Linux, macOS or Windows; amd64 or arm64), verifies its SHA-256 against the release's checksums.txt, and runs logscrub --check --report on the files; the step fails if anything would be masked. version selects the release (latest by default; pin one for reproducible builds). Inputs reach the script through the environment, never by interpolation, and the version is restricted to a release number, so a workflow input cannot inject commands or change the download URL.
There is deliberately no moving v1 tag: tags here are immutable and each one publishes a release, so pin an exact version (Dependabot can bump it).
repos:
- repo: https://github.com/hbenali/logscrub
rev: 1.1.0
hooks:
- id: logscrub
# args: [--config, .github/logscrub.toml]pre-commit builds logscrub from source, so Go must be installed. The hook fails the commit if a staged text file would be masked and prints counts per detector, never the text.
--report prints counts per detector (never the matched text). --report-format json and sarif also list where each match is:
logscrub --check --report --report-format json build.log # to stdout with --check
logscrub --check --report --report-format sarif build.log > logscrub.sarif-
JSON:
total,counts, andfindingswithfile,line,column(1-based, counted in bytes),byte_offset,byte_lengthanddetector(plusend_linefor private key blocks that span lines). Listing is capped at 100,000 findings;findings_truncatedsays so and the counts stay exact. -
SARIF 2.1.0: one rule per detector, one result per match with the line and byte range. GitHub code scanning accepts it (
github/codeql-action/upload-sarif), so findings show up as alerts on the file and line.
Reports never contain the text that was found, so they are safe to upload as CI artifacts. The file name is the path you passed (stdin for standard input).
logscrub -o clean.log app.log writes the cleaned text to a file: atomically (a failed run never leaves a half-written file or replaces the old one), with mode 0600, and it refuses to overwrite a file it is reading. The shell equivalent, logscrub app.log > clean.log, works too; -o is for when you want those guarantees.
logscrub reads a per-user config ($XDG_CONFIG_HOME/logscrub/config.toml, if it exists and is not world-writable) and an explicit --config FILE. It deliberately does not look for a config in the current directory: an allow-list in an untrusted checkout could make logscrub leak what it was asked to mask. In CI, pass your committed config explicitly:
logscrub --config .github/logscrub.toml --check build.logUse --no-config to ignore the per-user file.
logscrub is open source. Docs live in docs/wiki.