Skip to content

Conversation

@MatMoore
Copy link
Contributor

@MatMoore MatMoore commented Oct 23, 2025

This is a fix to the change we made in #280 in order to avoid secret scanning blocking our PR workflow.

Either this has never worked, or the param changed, but currently the depth param is being ignored, meaning only the latest commit is checked out as part of the CI. However, the intention here was to fetch all ancestor commits of the current branch (but not the entire repository) so that secret scanning is able to scan every commit in the PR.

After fixing the param, I tested this by pushing two commits: first one with a fake credential in, second one that removes the credential. It correctly failed the check.

Note: regardless of what this PR check is doing, the entire git history is still scanned on main, so secrets cannot slip through without us being alerted.

either this has never worked, or the param changed, but currently this
is being ignored, meaning only the latest commit is scanned. The
intention here was to scan all anscestor commits of the current
branch.

note: the entire git history is still scanned on main
@MatMoore MatMoore changed the title fix parameter name fix parameter name in checkout action Oct 23, 2025
@MatMoore MatMoore force-pushed the fix-pr-level-secret-scan branch from 5279738 to f5e5e7d Compare October 23, 2025 09:31
@MatMoore MatMoore marked this pull request as ready for review October 23, 2025 09:37
@MatMoore MatMoore merged commit 2edcca9 into main Oct 23, 2025
24 checks passed
@MatMoore MatMoore deleted the fix-pr-level-secret-scan branch October 23, 2025 16:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants