Add TruffleHog secret scan workflow

master
Carlo Costanzo 2 weeks ago
parent 1baee9b684
commit b7268a632a

@ -0,0 +1,36 @@
######################################################################
# @CCOSTAN - Follow Me on X
# For more info visit https://www.vcloudinfo.com/click-here
# Original Repo : https://github.com/CCOSTAN/Home-AssistantConfig
# -------------------------------------------------------------------
# Secret Scan Workflow - TruffleHog credential leak detection.
# Runs verified-only secret scanning on pull requests, master pushes,
# and manual dispatch without adding local commit-hook friction.
# -------------------------------------------------------------------
######################################################################
name: Secret Scan
on:
pull_request:
push:
branches: ["master"]
workflow_dispatch:
permissions:
contents: read
jobs:
trufflehog:
name: TruffleHog
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Scan for verified secrets
uses: trufflesecurity/trufflehog@v3.95.3
with:
version: v3.95.3
extra_args: --results=verified --force-skip-binaries --force-skip-archives
Loading…
Cancel
Save

Powered by TurnKey Linux.