Picket Secret Scanner
Version updated for https://github.com/willibrandon/picket to version v0.2.8.
- This action is used across all versions by ? repositories.
Action Type
This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary
Picket is a MIT-licensed secrets scanner for .NET that provides a Gitleaks-compatible command surface, Picket-native scanning capabilities, Native AOT release binaries, dotnet tool packages, and embeddable AOT-safe libraries. It can scan staged, unstaged, and untracked Git changes, Hugging Face models, datasets, Spaces, or buckets with read-only tokens stored in an environment variable, and GitLab issues, comments, releases, and release assets. The action supports CI integrations for GitHub Actions and Azure Pipelines, and it provides a Coding Agent Guards tool to inspect Codex and Claude hook events. Picket also publishes embeddable packages for rules, scanning, reporting, security, and documentation.
What’s Changed
Release artifacts include SHA-256 checksums, package-size metadata, and GitHub artifact attestations.