File tree Expand file tree Collapse file tree 1 file changed +2
-11
lines changed Expand file tree Collapse file tree 1 file changed +2
-11
lines changed Original file line number Diff line number Diff line change 1
1
name : Secret Scan
2
-
3
2
on : [pull_request, merge_group]
4
-
5
3
jobs :
6
4
secret-scan :
7
5
name : Secret Scan
8
6
runs-on : ubuntu-latest
9
7
permissions :
10
8
contents : " read"
11
-
12
9
outputs :
13
10
latest_release : ${{ steps.trufflehog_release.outputs.latest_release }}
14
11
latest_tag_name : ${{ steps.trufflehog_release.outputs.latest_tag_name }}
15
-
16
12
steps :
17
13
- name : Checkout Code
18
14
uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
19
-
20
15
- name : Install Cosign
21
16
uses : sigstore/cosign-installer@59acb6260d9c0ba8f4a2f9d9b48431a222b68e20 # v3.5.0
22
-
23
17
- name : Pin Trufflehog to a know good release
24
18
id : trufflehog_release
25
19
shell : bash
29
23
# echo "latest_tag_name=$LATEST_TAG_NAME" >> "$GITHUB_OUTPUT"
30
24
# echo "latest_release=$LATEST_RELEASE" >> "$GITHUB_OUTPUT"
31
25
run : |
32
- echo "latest_tag_name=v3.88.25" >> "$GITHUB_OUTPUT"
33
- echo "latest_release=3.88.25" >> "$GITHUB_OUTPUT"
34
-
26
+ echo "latest_tag_name=v3.89.2" >> "$GITHUB_OUTPUT"
27
+ echo "latest_release=3.89.2" >> "$GITHUB_OUTPUT"
35
28
- name : Download and verify TruffleHog release
36
29
run : |
37
30
curl -sLO https://github.com/trufflesecurity/trufflehog/releases/download/${{ steps.trufflehog_release.outputs.latest_tag_name }}/trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt
@@ -46,12 +39,10 @@ jobs:
46
39
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"
47
40
48
41
sha256sum --ignore-missing -c trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_checksums.txt
49
-
50
42
- name : Extract TruffleHog
51
43
run : |
52
44
tar xzf trufflehog_${{ steps.trufflehog_release.outputs.latest_release }}_linux_amd64.tar.gz -C /usr/local/bin
53
45
chmod +x /usr/local/bin/trufflehog
54
-
55
46
- name : Run TruffleHog scan
56
47
continue-on-error : true
57
48
id : scan
You can’t perform that action at this time.
0 commit comments