From 67c6edb65c1ef05a4084774f924a766bfbe620d6 Mon Sep 17 00:00:00 2001 From: Tanvir Date: Tue, 6 Aug 2024 16:00:12 +0600 Subject: [PATCH] add trufflehog github workflow --- .github/workflows/trufflehog.yml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 .github/workflows/trufflehog.yml diff --git a/.github/workflows/trufflehog.yml b/.github/workflows/trufflehog.yml new file mode 100644 index 0000000..f93ba21 --- /dev/null +++ b/.github/workflows/trufflehog.yml @@ -0,0 +1,26 @@ +name: Trufflehog +on: [pull_request, push, workflow_dispatch] + +jobs: + trufflehog: + name: trufflehog + runs-on: ubuntu-latest + + steps: + - name: Checkout code + uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Secret Scanning + uses: trufflesecurity/trufflehog@main + with: + extra_args: --only-verified + + # Scan entire branch + - name: scan-push + uses: trufflesecurity/trufflehog@main + with: + base: "" + head: ${{ github.ref_name }} + extra_args: --only-verified