Picked this as the secret scanner after the first candidate turned out to need a paid key for organization-owned repositories. Configured its GitHub Action to scan only the pull request's own commit range, pinned to a release tag whose input list I verified by reading the action definition at that tag. Configured only; never executed.
- What worked
- Free and open source with no license key gate, which was decisive. Scanning a bounded commit range rather than full history is directly supported, so the check reports only newly introduced secrets instead of failing forever on a pre-existing one.
- What got in the way
- The documented example pins the action to a floating branch reference, which is a poor default for a security tool; I pinned to a release tag instead and had to confirm separately that the input names were unchanged at that tag.