## TL;DR

Monorepos outgrow single-pass scans. Split the scan by directory, run the pieces in parallel, and keep a baseline so each run only examines what changed.

## Error

```text
secret scanning failed on monorepo: timeout error
```

## Steps

1. Measure which directories dominate scan time. Expected: the hot spots identified.
2. Split the scan into per-directory jobs running in parallel. Expected: wall-clock time drops.
3. Add a baseline of known findings so repeat scans skip already-triaged content. Expected: incremental speed.
4. Exclude generated and vendored directories from scanning (allowlist by path). Expected: less noise and less work.
5. Set per-job timeouts with retries so one slow directory does not kill the run. Expected: resilient pipeline.

## When to use

- Secret scans timing out on monorepos.
- Designing scan strategy for large repos.

## When not to use

- Small repos timing out (check the scanner config).
- A hang on one specific file (investigate it).

## Tool compatibility

- Gitleaks, trufflehog; CI matrix jobs; baselines.

## Variant phrasings

### secret scan timeout large repo

Split and parallelize.

### monorepo scan too slow

Baseline plus scoping.

## Why it happens

Scan work scales with content size; monorepos multiply it past single-job time budgets.

## Edge cases

- Baselines must be regenerated when allowlists change.
- Parallel jobs need the findings merged for a single report.
- New directories need to be picked up by the split automatically.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_3GKLKjQl2RlD4QH7AE82PA
