File tree Expand file tree Collapse file tree 2 files changed +32
-0
lines changed Expand file tree Collapse file tree 2 files changed +32
-0
lines changed Original file line number Diff line number Diff line change
1
+ name : Secrets Scan
2
+ on :
3
+ pull_request :
4
+ types : [opened, synchronize, reopened]
5
+ jobs :
6
+ security-secrets :
7
+ runs-on : ubuntu-latest
8
+ steps :
9
+ - uses : actions/checkout@v4
10
+ with :
11
+ fetch-depth : ' 2'
12
+ ref : ' ${{ github.event.pull_request.head.ref }}'
13
+ - run : |
14
+ git reset --soft HEAD~1
15
+ - name : Install Talisman
16
+ run : |
17
+ # Download Talisman
18
+ wget https://github.com/thoughtworks/talisman/releases/download/v1.37.0/talisman_linux_amd64 -O talisman
19
+
20
+ # Checksum verification
21
+ checksum=$(sha256sum ./talisman | awk '{print $1}')
22
+ if [ "$checksum" != "8e0ae8bb7b160bf10c4fa1448beb04a32a35e63505b3dddff74a092bccaaa7e4" ]; then exit 1; fi
23
+
24
+ # Make it executable
25
+ chmod +x talisman
26
+ - name : Run talisman
27
+ run : |
28
+ # Run Talisman with the pre-commit hook
29
+ ./talisman --githook pre-commit
Original file line number Diff line number Diff line change 1
1
threshold: medium
2
2
3
3
fileignoreconfig:
4
+ - filename: .github/workflows/secrets-scan.yml
5
+ ignore_detectors:
6
+ - filecontent
4
7
- filename: README.md
5
8
checksum: b9cad0b376230ea7079fef3459f233b2c61f3d5e48d6d5d03a6bf3e2d39117a8
You can’t perform that action at this time.
0 commit comments