Is it possible to find secrets in .env and .gitlab-ci.yml?

Sonar is now able to scan .env files.

See Sonar now analyzes “dotfiles” for secrets for more details.