aldabra/.forgejo/workflows/gitleaks.yml

33 lines
940 B
YAML

# .forgejo/workflows/gitleaks.yml
#
# Scans the repository for committed secrets with gitleaks on every push and
# pull request. Use it as a required status check via branch protection so a
# leaking change cannot be merged. Works the same on GitHub Actions if you
# move the file to `.github/workflows/`.
name: gitleaks
on:
push:
pull_request:
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
# Full history — gitleaks needs depth to scan a commit range.
fetch-depth: 0
- name: install gitleaks
run: |
curl -sSL -o gl.tar.gz \
https://github.com/gitleaks/gitleaks/releases/download/v8.21.2/gitleaks_8.21.2_linux_x64.tar.gz
tar xzf gl.tar.gz gitleaks
chmod +x gitleaks
./gitleaks version
- name: scan
run: |
./gitleaks detect --source . --no-banner --redact --verbose