{"actions":{"bootstrapAndRun":{"effect":"installs rote if missing, inspects, prepares, and asks before running","href":"https://play.modiqo.ai/install?play=himanshu-jha/git-history-secret-scan@0.7.2","method":"GET","rel":"https://rote.dev/rels/bootstrap-and-run","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"inspect":{"command":"rote play inspect https://play.modiqo.ai/himanshu-jha/git-history-secret-scan@0.7.2","effect":"read-only"},"installCliOnly":{"effect":"installs the rote CLI, nothing else","href":"https://play.modiqo.ai/install","method":"GET","rel":"https://rote.dev/rels/install-cli","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"run":{"command":"rote play run https://play.modiqo.ai/himanshu-jha/git-history-secret-scan@0.7.2","effect":"executes the play locally after consent","headless":{"approvalAssertion":"--yes","approvalRequiredBeforeInvocation":true,"commandTemplate":"rote play run https://play.modiqo.ai/himanshu-jha/git-history-secret-scan@0.7.2 <name=value...> --yes","stdinPolicy":"never pipe input to automate the interactive Ready selector"},"requiresConsent":true}},"description":"Finds credentials that live in git history, not just the working tree. Deleting a .env and committing does not remove it: every blob ever committed stays reachable, and a hackathon repo is usually made public at submission time. Three independent stages run as parallel DAG steps (history blob scan across every ref, env files that were ever committed, and and whether the repository it is pushed to is actually public, asked of your own gh session rather than assumed from the host), then one join weighs each finding against that exposure. A stage that cannot complete becomes a labeled indeterminate rather than a silent pass, and every report states how many objects it actually walked, because a partial scan and a clean repository must not read the same. Read-only: never rewrites history, never mutates the repository. It makes no network call of its own: the one optional lookup shells out to your existing gh login, and when gh is missing or logged out the report says the visibility was not resolved and why, rathe","distribution":{"digest":"sha256:5e742215df2fb5df6b5c6fd62393ba18a7e4f11e02087a7675e51c15f6affc6c","mediaType":"application/vnd.modiqo.rote-flow","size":15482,"verifiedBy":"rote verifies the downloaded archive against this digest before it runs"},"effects":{"credentialsProvidedBy":"runner","credentialsRemainLocal":true,"declaredWrites":[],"publisherReceivesCredentials":false},"id":"https://play.modiqo.ai/himanshu-jha/git-history-secret-scan@0.7.2","inputPolicy":{"optionalWithDefault":"show_default_and_accept_override","optionalWithoutDefault":"omit_unless_supplied","required":"ask","secrets":"collect_locally_outside_conversation"},"license":"MIT","links":{"docs":"https://rote.dev","page":"https://play.modiqo.ai/himanshu-jha/git-history-secret-scan@0.7.2","protocol":"https://play.modiqo.ai/.well-known/rote","self":"https://play.modiqo.ai/himanshu-jha/git-history-secret-scan@0.7.2.json"},"name":"git-history-secret-scan","owner":{"kind":"org","slug":"himanshu-jha"},"parameters":[{"description":"Absolute path to the repository to scan. Leave it out and the most recently committed repository found under your usual project directories is scanned instead, with the report naming which one it chose. A relative path is never right here: steps run in the play run workspace, not your shell.","example":"/Users/me/src/my-entry","input":{"allowCustom":true,"choices":[],"label":"Repo"},"name":"repo","required":false,"type":"string"},{"default":"20000","description":"Maximum history objects to walk. A scan that hits this limit says so in its report rather than reporting a clean result it did not earn. Raise it for a large repository.","example":"20000","input":{"allowCustom":true,"choices":[],"label":"Budget"},"name":"budget","required":false,"type":"string"}],"preparation":[{"action":{"command":"rote play inspect https://play.modiqo.ai/himanshu-jha/git-history-secret-scan@0.7.2 --json","effect":"read-only"},"step":1,"type":"inspect_local_readiness"},{"references":["/parameters"],"step":2,"type":"collect_parameters"},{"references":["/parameters","/requirements","/effects"],"step":3,"type":"review"},{"consentBoundary":"the user approves the exact play and parameter values","references":["/parameters","/requirements","/effects"],"step":4,"type":"obtain_run_consent"},{"action":{"command":"rote play run https://play.modiqo.ai/himanshu-jha/git-history-secret-scan@0.7.2","headlessCommandTemplate":"rote play run https://play.modiqo.ai/himanshu-jha/git-history-secret-scan@0.7.2 <name=value...> --yes"},"preservesAcquisitionBoundaries":["adapter_selection","oauth_dcr","google_discovery","static_token_setup","runtime_security_checks"],"requiresConsent":true,"step":5,"type":"run"}],"producedBy":{"roteVersion":"0.75.0"},"publishedAt":"2026-09-02T18:32:21.258653+00:00","reference":"himanshu-jha/git-history-secret-scan@0.7.2","requirements":{"adapters":[],"browser":{"dependencies":[],"runtime":false,"signIn":false},"localTools":["python3","git","gh"],"roteCli":{"minimumVersion":"0.62.0"},"sessions":false},"resolution":"pinned","schema":"rote.play.v1","stats":{"downloads":4,"installs":0},"steps":{"count":5,"names":["assess_exposure","remote_exposure","scan_history_blobs","tracked_env_files","validate_history"]},"title":"git-history-secret-scan","type":"play","version":"0.7.2","visibility":"public"}