Sign inSign up

docker/sbx-kit-gitguardian:1.53.0

Multi-platform
Manifest digest

sha256:6234ccbc863da704d5d4523b546e8c110b2f006b308706925afb9508e03f6579

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:6234ccbc863da704d5d4523b546e8c110b2f006b308706925afb9508e03f6579

yaml
schemaVersion: "3"
displayName: GitGuardian (ggshield)
description: Installs the GitGuardian CLI (ggshield) with proxy-injected API-key auth for api.gitguardian.com and wires it as a Claude Code AI hook, so the agent's actions are scanned for hardcoded secrets automatically - the real key never enters the sandbox.
version: 1.53.0
kind: mixin
provides:
    - [email protected]
requires:
    - claude
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - api.gitguardian.com
    - type: com.docker.sandbox/credential@1
      config:
        apiKey:
            inject:
                - domain: api.gitguardian.com
                  format: Token %s
                  header: Authorization
            name: GITGUARDIAN_API_KEY
            proxyManaged: true
        phase: runtime
        service: gitguardian
      description: GitGuardian API key (from a Personal or Service Account, "scan" scope). Stored on the host; the sandbox only sees a placeholder and the proxy injects the real value on requests to api.gitguardian.com.
    - type: com.docker.sandbox/lifecycle@1
      config:
        install:
            - command: |
                set -euo pipefail
                export GITGUARDIAN_API_KEY="${GITGUARDIAN_API_KEY:-proxy-managed}"
                ggshield machine setup --agent claude-code --no-git-hooks --no-honeytokens
                echo "ggshield AI hook installed (~/.claude/settings.json)"
              description: Install ggshield as a Claude Code AI hook (agent user)
              env:
                - GITGUARDIAN_API_KEY
              user: "1000"
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/gitguardian/gitguardian-context.md
args:
    version:
        default: 1.53.0
        description: ggshield release to install
        pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
        buildArg: GGSHIELD_VERSION