cardano-api/.forgejo/workflows/gitleaks.yml

32 lines
908 B
YAML

# Gitleaks secret-scanning workflow.
#
# Scans the repository for committed secrets on every push and pull request,
# so credentials never land in history unnoticed. It runs on a Forgejo/Gitea
# Actions runner; copy it to .github/workflows/ to run it on GitHub Actions too.
name: gitleaks
on:
push:
pull_request:
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
# Full history — gitleaks needs depth to scan a commit range.
fetch-depth: 0
- name: install gitleaks
run: |
curl -sSL -o gl.tar.gz \
https://github.com/gitleaks/gitleaks/releases/download/v8.21.2/gitleaks_8.21.2_linux_x64.tar.gz
tar xzf gl.tar.gz gitleaks
chmod +x gitleaks
./gitleaks version
- name: scan
run: |
./gitleaks detect --source . --no-banner --redact --verbose